How to filter alert display between addresses? #12072
Replies: 1 comment
-
Since you used the word SOC Alerts is a simplified version of SOC Dashboards but you can toggle the
https://docs.securityonion.net/en/2.4/dashboards.html#oql
From https://docs.securityonion.net/en/2.4/dashboards.html#query-bar: Specifically see https://docs.securityonion.net/en/2.4/soc-customization.html#custom-queries. |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
I'd like to not show alerts on the dashboard between two addresses, how can I do this?
I do not want to keep Suricata from generating alerts, I just want to not show any alerts between certain IP addresses. What is the filter syntax and where do I enter it? Am I able to save the filters?
Beta Was this translation helpful? Give feedback.
All reactions