2.3.260 not disabling rule 2018959 #11359
-
Hi there We are having difficulty disabling a specific rule in suricata - 2018959. Any ideas?? |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
Here's the full rule for SID 2018959:
Notice that it sets a flowbit:
Please see https://docs.securityonion.net/en/2.3/managing-alerts.html#flowbits for a full explanation of flowbits. |
Beta Was this translation helpful? Give feedback.
Here's the full rule for SID 2018959:
Notice that it sets a flowbit:
Please see https://docs.securityonion.net/en/2.3/managing-alerts.html#flowbits for a full explanation of flowbits.