NIDS tuning with source and destination IPs #13888
-
Version2.4.110 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU4 RAM32 Storage for /100 Storage for /nsm1000 Network Traffic Collectionspan port Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailI'm trying to tune a NIDS detection using the ETPRO ruleset. I have one rule that triggers on traffic between two particular hosts, and I want to suppress the alert. That is I want to suppress if the source is (e.g.) 1.1.1.1 AND the destination is (e.g.) 2.2.2.2. Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment
-
You can't suppress for a source and destination pairing, it's either one or the other. You could implement this with a custom flowbit, per this post on the Suricata forum: https://forum.suricata.io/t/rule-threshold-configuration/2461 |
Beta Was this translation helpful? Give feedback.
You can't suppress for a source and destination pairing, it's either one or the other.
You could implement this with a custom flowbit, per this post on the Suricata forum:
https://forum.suricata.io/t/rule-threshold-configuration/2461