Skip to content
Discussion options

You must be logged in to vote

You should be able to disable all of the default Suricata rules by using a regex like "ET/s".

Docs: https://docs.securityonion.net/en/2.4/nids.html#enabling-and-disabling-with-regex

Replies: 3 comments 2 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by Anadema
Comment options

You must be logged in to vote
2 replies
@InfosecGoon
Comment options

@Anadema
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants