Skip to content
Discussion options

You must be logged in to vote

Check out the thresholding and suppressions section of this https://docs.securityonion.net/en/2.3/managing-alerts.html

will look something like below and one thing to note, make sure you get the spacing correct as YAML is very particular with its formatting

thresholding:
  sids:
    2012454:
      - suppress:
          gen_id: 1
          track: by_dst/by_src
          ip: 

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@presianbg
Comment options

Answer selected by dougburks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
3 participants