Skip to content
Discussion options

You must be logged in to vote

when i read my message again i see its a bit missunderstanding.

So this is right. you just put it in the wrong place.

2012843:
  - suppress:
      gen_id: 1
      track: by_src
      ip: 192.168.7.0/24
2034771:
  - suppress:
      gen_id: 1
      track: by_src
      ip: 192.168.7.0/24
      

The above needs to go into:

-> suricata

-> thresholding

SIDS

2012843:
  - suppress:
      gen_id: 1
      track: by_src
      ip: 192.168.7.0/24
2034771:
  - suppress:
      gen_id: 1
      track: by_src
      ip: 192.168.7.0/24
      

If you want to disable a rule completly, you can simply add the rule.uuid in:

-> sids

-> disabled
2034771

Replies: 3 comments 20 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
20 replies
@killmasta93
Comment options

@izidood
Comment options

@killmasta93
Comment options

@izidood
Comment options

Answer selected by killmasta93
@killmasta93
Comment options

@izidood
Comment options

@killmasta93
Comment options

@izidood
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
3 participants