| Search Site |
| Search Rules |
| Account |
| not registered? |
| can't login? |
| user preferences |
|
|||||||||||||||||||||||
|
Next: Format Up: Writing Snort Rules: How Previous: Global Thresholds Contents Event SuppressionEvent suppression stops specified events from firing without removing the rule from the rule base. Suppression uses a CIDR block notation to select specific networks and users for suppression. Suppression tests are performed prior to either standard or global thresholding tests.Suppression commands are standalone commands that reference generators, SIDs, and IP addresses via a CIDR block. This allows a rule to be completely suppressed, or suppressed when the causative traffic is going to or coming from a specific IP or group of IP addresses. You may apply multiple suppression commands to a SID. You may also combine one threshold command and several suppression commands to the same SID.
Subsections Steven Sturges 2007-05-11 |
|||||||||||||||||||||||
|
|||||||||||||||||||||||