Skip to content
Discussion options

You must be logged in to vote

I assume you mean Suricata alerts? You can't modify the rule list for a single Forward Node, because the rule list is compiled on the Manager and then pushed out to the Forward Nodes as a completed entity. If there are particular rules you want to suppress from particular networks, would modifying the rule to ignore particular source IPs or subnets work for your use case?

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@cherryCokeBack
Comment options

Answer selected by cherryCokeBack
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants