Skip to content

Changing Suricata "Threshold SIDS List" #13619

Answered by cm-ops
ejgh-oe asked this question in 2.4
Discussion options

You must be logged in to vote

Through Detections is the recommended way to tune. How many rules are you looking to suppress/threshold? What do you have in /opt/so/saltstack/local/salt/suricata/thresholding/sids.yaml? The threshold.conf gets populated from that file.

Replies: 1 comment 8 replies

Comment options

You must be logged in to vote
8 replies
@ejgh-oe
Comment options

@cm-ops
Comment options

@ejgh-oe
Comment options

@cm-ops
Comment options

Answer selected by ejgh-oe
@ejgh-oe
Comment options

@cm-ops
Comment options

@ejgh-oe
Comment options

@ejgh-oe
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants