-
I have scan engines on the lan that I would like to exclude from NIDS completely, and I had a BPF Filter in /opt/so/saltstack/local/pillar/global.sls as per documentation here: https://docs.securityonion.net/en/2.3/bpf.html For some reason this is not being picked up and filtered out. How can I diagnose the issue further? |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments
-
Are you able to share the exact BPF syntax in Are you able to share the contents of Are you able to share the output of |
Beta Was this translation helpful? Give feedback.
-
Seems like the issue was temporary after the upgrade, which led to a bunch of alerts, but then sorted itself out. Thanks Doug! |
Beta Was this translation helpful? Give feedback.
Seems like the issue was temporary after the upgrade, which led to a bunch of alerts, but then sorted itself out. Thanks Doug!