Question on supressing alerts #12378
-
Hi i was reading https://docs.securityonion.net/en/2.4/managing-alerts.html#disable-the-alert as they say suppress but from a specific ID and i want to suppress all from a certain IP would it be like this but not sure if thats correct
|
Beta Was this translation helpful? Give feedback.
Replies: 3 comments 20 replies
-
It would be easier to utilize a Suricata BPF to filter out that IP. https://docs.securityonion.net/en/2.4/bpf.html |
Beta Was this translation helpful? Give feedback.
-
hi @robbiemarshall i was reading a bit on the doc you sent me would be something like this? out of curiosity if i would want to also suppress the alert ET POLICY Cleartext WordPress Login would it be something like this |
Beta Was this translation helpful? Give feedback.
-
In the first picture, you'd want to put that in suricata instead of pcap. In the second pic, that looks correct. |
Beta Was this translation helpful? Give feedback.
when i read my message again i see its a bit missunderstanding.
So this is right. you just put it in the wrong place.
The above needs to go into:
If you want to disable a rule completly, you can simply add the rule.uuid in: