Skip to content
Discussion options

You must be logged in to vote

The link you used was a section of documentation that had not been fully updated for 2.4:
https://docs.securityonion.net/en/2.4/suricata.html?highlight=suricata#thresholding

That link has been updated to point to the Managing Alerts section:
https://docs.securityonion.net/en/2.4/managing-alerts.html#threshold

Please try that and see if it works. Please note that your config should start with the SID (so unlike 2.3 you shouldn't need the thresholding: and sids: lines).

Replies: 2 comments 3 replies

Comment options

You must be logged in to vote
1 reply
@sleepingbel
Comment options

Comment options

You must be logged in to vote
2 replies
@sleepingbel
Comment options

@sleepingbel
Comment options

Answer selected by sleepingbel
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
3 participants