How to suppress multiple IP's for 1 suricata rule, this is not docummented #13169
-
Version2.4.70 Installation MethodSecurity Onion ISO image Descriptionupgrading Installation TypeStandalone Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU16 v-CPU RAM48 GB Storage for /250 GB Storage for /nsm1.66 TB Network Traffic Collectionspan port Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailHow can we add multiple IP for surpressing for the Suricata Rules, there is no mention of it in the manual When I add the IP to the first surpress filter with a comma between the two IP's i get this message and it is not possible to save If I try to add two surpress filters I get this alert, what in my point of view is correct because you need to add the IP to the first filter. Regards Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
I added another condition and track on the same rule with the second IP, and did for additional as well -- seems to have worked for me. |
Beta Was this translation helpful? Give feedback.
I added another condition and track on the same rule with the second IP, and did for additional as well -- seems to have worked for me.