Can I block a specific IP for all alerting #14064
-
Version2.4.111 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeStandalone Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU8 RAM32 Storage for /2TB Storage for /nsm1TB Network Traffic Collectionspan port Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusYes, there are salt failures (please provide detail below) LogsNo, there are no additional clues DetailI need to block another security appliance from throwing alerts in SO that is with the same LAN subnet. I know I can block via a specific rule in detections but and hoping to avoid tedious work. Thanks. Guidelines
|
Beta Was this translation helpful? Give feedback.
Answered by
rh-ops
Jan 3, 2025
Replies: 1 comment
-
You can use a BPF filter to exclude that appliance via its IP. |
Beta Was this translation helpful? Give feedback.
0 replies
Answer selected by
jashbaugh-c1
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
You can use a BPF filter to exclude that appliance via its IP.
https://docs.securityonion.net/en/2.4/bpf.html