-
As the title indicates, I'm looking for examples when tuning, specifically when using the modify choice. In my case, I have a couple rules where I'd like a couple parent domains to not trigger perl or curl user-agent rules. If I wanted to "whitelist" say microsoft.com, where can I find what that would look like? |
Beta Was this translation helpful? Give feedback.
Answered by
cm-ops
Jul 22, 2024
Replies: 1 comment 7 replies
-
You could add a content keyword https://docs.suricata.io/en/suricata-7.0.5/rules/payload-keywords.html something like |
Beta Was this translation helpful? Give feedback.
7 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Rule after modify: