[Snort-users] Event Suppression between specific Source and Destination

Joel Esler jesler at ...1935...
Fri Dec 14 10:20:04 EST 2012


On Fri, Dec 14, 2012 at 11:04:23AM +0100, Guido Hungerbuehler wrote:
> Hi
> 
> I am running snort with alert-before-log configuration (it is 
> necessary). How can I suppress a signature between two specific hosts?
> 
> With the 'Event Suppression' configuration it is only possible to select 
> either track by_src or track by_dst.
> 
> The next question is: Why is this even like this for 'Event Suppression'?
> 
> I already searched the mailing-list archive because I think this issue 
> has to be discussed earlier but I didn't find any information.
> 
> 
> Thanks for your help.


If you suppress it in one direction, then you won't see the alert.  If you bi directional traffic that you want to suppress, you need to create two suppressions

--
Joel Esler
Senior Research Engineer, VRT
OpenSource Community Manager
Sourcefire




More information about the Snort-users mailing list