Suppressing Rules

Problem

You want to suppress a rule without permanently removing it from the ruleset.

Solution

Use the suppress command to suppress a rule.

suppress gen_id , sid_id 

 

Discussion

Suppression allows you to deactivate a rule completely. The options are gen_id and sig_id. Gen_id is the generator ID, and sig_id is the Snort signature ID.

To suppress an event entirely:

suppress gen_id 1, sig_id 1234

 

See Also

Snort User Manual

Recipe 3.17

Thresholding Alerts

Installing Snort from Source on Unix

Logging to a File Quickly

How to Build Rules

Detecting Stateless Attacks and Stream Reassembly

Managing Snort Sensors

Generating Statistical Output from Snort Logs

Monitoring Network Performance

Index

show all menu



Snort Cookbook
Snort Cookbook
ISBN: 0596007914
EAN: 2147483647
Year: 2006
Pages: 167
Similar book on Amazon

Flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net