Skip to content
Discussion options

You must be logged in to vote

Im looking to tune it to filter out some alerts

From https://docs.securityonion.net/en/2.3/tuning.html:
To get the best performance out of Security Onion, you’ll want to tune it for your environment. Start by creating Berkeley Packet Filters (BPFs) to ignore any traffic that you don’t want your network sensors to process. Then tune your IDS rulesets. There may be entire categories of rules that you want to disable first and then look at the remaining enabled rules to see if there are individual rules that can be disabled.

Can someone point me to more specific video's documents please?
Specific questions >
Where do i go to stop a specific alert from a IP address? (is if BPF filter? ) - …

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@wilmerism
Comment options

Answer selected by wilmerism
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants