Skip to content
Discussion options

You must be logged in to vote

@s0meguy1 Double-check your yaml syntax here:

     2027870:
    - suppress:
        gen_id: 1
        ip: 192.168.0.94
        track: by_src

Per https://docs.securityonion.net/en/2.3/managing-alerts.html, that section should start with:

thresholding:
  sids:

and then make sure each line is indented properly.

Suppressions should apply directly to Suricata instead of idstools.

Replies: 4 comments 6 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
3 replies
@s0meguy1
Comment options

@dougburks
Comment options

@s0meguy1
Comment options

Answer selected by s0meguy1
Comment options

You must be logged in to vote
3 replies
@sanba06c
Comment options

@s0meguy1
Comment options

@sanba06c
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
3 participants
Converted from issue

This discussion was converted from issue #8818 on September 27, 2022 12:33.