How to add or delete the node by yaml-cpp? and how to save comment by yaml-cpp?

Viewed 138

How to parse or add or delete the node

How do you add a node like this

 af-packet:
      - interface: eth1
      - interface: eth2
      - interface: eth3

how to delete - interface: eth1 or delete all interface

 af-packet:
      - interface: eth1
      - interface: eth2
      - interface: eth3

how to save comment?

std::ofstream file(strSuricatatFilename);
file << suricateCfg;
file.close();

Such code comments will disappear

Can I keep the first two lines?

whole file:

    %YAML 1.1
    ---
    
    # Suricata configuration file. In addition to the comments describing all
    # options in this file, full documentation can be found at:
    # https://suricata.readthedocs.io/en/latest/configuration/suricata-yaml.html
    
    ##
    ## Step 1: inform Suricata about your network
    ## 
af-packet:
  - interface: eth1
  - interface: eth6

  #- interface: eth0
  
    # Number of receive threads. "auto" uses the number of cores
    #threads: auto
    # Default clusterid. AF_PACKET will load balance packets based on flow.
    cluster-id: 99
    # Default AF_PACKET cluster type. AF_PACKET can load balance per flow or per hash.
    # This is only supported for Linux kernel > 3.1
    # possible value are:
    #  * cluster_flow: all packets of a given flow are send to the same socket
    #  * cluster_cpu: all packets treated in kernel by a CPU are send to the same socket
    #  * cluster_qm: all packets linked by network card to a RSS queue are sent to the same
    #  socket. Requires at least Linux 3.14.
    #  * cluster_ebpf: eBPF file load balancing. See doc/userguide/capture-hardware/ebpf-xdp.rst for
    #  more info.
    # Recommended modes are cluster_flow on most boxes and cluster_cpu or cluster_qm on system
    # with capture card using RSS (require cpu affinity tuning and system irq tuning)
    cluster-type: cluster_flow
    # In some fragmentation case, the hash can not be computed. If "defrag" is set
    # to yes, the kernel will do the needed defragmentation before sending the packets.
    defrag: yes
    # To use the ring feature of AF_PACKET, set 'use-mmap' to yes

thanks.

0 Answers
Related