Snort - the de facto standard for intrusion detection/prevention
next up previous contents
Next: Examples Up: Event Suppression Previous: Event Suppression   Contents

Format

The suppress command supports either 2 or 4 options, as described in Table [*].


Table: Suppression Options
Option Argument Required?
gen_id $<$generator id$>$ required
sig_id $<$Snort signature id$>$ required
track by_src or by_dst optional, requires ip
ip ip[/mask] optional, requires track

suppress gen_id <gen-id>, sig_id <sig-id>, \
    track <by_src|by_dst>, ip <ip|mask-bits>



Steven Sturges 2007-10-04