Manivel
Sharing my technical knowledge
Sunday, 12 January 2014
Ignore a specific alert for specific IP address in Snort
If we want to ignore a specific snort rule for specific IP or network, we can use "suppression" in threshold.conf file under /etc/snort.
[root@snort rules]# vim /etc/snort/threshold.conf
No comments:
Post a Comment
Newer Post
Older Post
Home
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment