Millions of triggered alerts #2024
-
Hello, I am getting loads of false alerts from what I think is a failure to use my After running for ~2 hours I have 25 million alerts. The subnet that triggers all these alerts are in the
The rules that triggers looks like this: So I did try to configure EXTERNAL_NET to be '!$HOME_NET' as mentioned in the documentation, but it still continues to trigger. Where should I start looking or what am I missing in the setup? SO version: 2.3.10 |
Beta Was this translation helpful? Give feedback.
Replies: 3 comments
-
Did you make sure the follow the guidance here? https://docs.securityonion.net/en/latest/suricata.html?highlight=HOME_NET#configuration |
Beta Was this translation helpful? Give feedback.
-
Yes, I think I was just not patient enough when I did this since it went away by itself during the evening. |
Beta Was this translation helpful? Give feedback.
Did you make sure the follow the guidance here? https://docs.securityonion.net/en/latest/suricata.html?highlight=HOME_NET#configuration