Delete rule for one forward node #12661
-
Version2.4.60 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU12 RAM64 Storage for /2to Storage for /nsm20to Network Traffic Collectionspan port Network Traffic Speedsmore than 10Gbps StatusYes, all services on all nodes are running OK Salt StatusYes, there are salt failures (please provide detail below) LogsNo, there are no additional clues DetailHello, after reading the documentation, I don't know if it's still possible with version 2.4.X. in the administration section we can delete a rule on all forward nodes thank you for your help have a nice day Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
I assume you mean Suricata alerts? You can't modify the rule list for a single Forward Node, because the rule list is compiled on the Manager and then pushed out to the Forward Nodes as a completed entity. If there are particular rules you want to suppress from particular networks, would modifying the rule to ignore particular source IPs or subnets work for your use case? |
Beta Was this translation helpful? Give feedback.
I assume you mean Suricata alerts? You can't modify the rule list for a single Forward Node, because the rule list is compiled on the Manager and then pushed out to the Forward Nodes as a completed entity. If there are particular rules you want to suppress from particular networks, would modifying the rule to ignore particular source IPs or subnets work for your use case?