Suppressing Rules

Table of contents:

Problem

You want to suppress a rule without permanently removing it from the ruleset.

Solution

Use the suppress command to suppress a rule.

suppress gen_id , sid_id 

 

Discussion

Suppression allows you to deactivate a rule completely. The options are gen_id and sig_id. Gen_id is the generator ID, and sig_id is the Snort signature ID.

To suppress an event entirely:

suppress gen_id 1, sig_id 1234

 

See Also

Snort User Manual

Recipe 3.17

Thresholding Alerts

Installing Snort from Source on Unix

Logging to a File Quickly

How to Build Rules

Detecting Stateless Attacks and Stream Reassembly

Managing Snort Sensors

Generating Statistical Output from Snort Logs

Monitoring Network Performance

Index



Snort Cookbook
Snort Cookbook
ISBN: 0596007914
EAN: 2147483647
Year: 2006
Pages: 167

Flylib.com © 2008-2020.
If you may any questions please contact us: flylib@qtcs.net