Skip to content

NIDS tuning with source and destination IPs #13888

Answered by InfosecGoon
rosswakelin asked this question in 2.4
Discussion options

You must be logged in to vote

You can't suppress for a source and destination pairing, it's either one or the other.

You could implement this with a custom flowbit, per this post on the Suricata forum:

https://forum.suricata.io/t/rule-threshold-configuration/2461

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by rosswakelin
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants