[Oisf-users] deciding what to drop in suricata IPS

Vieri rentorbuy at yahoo.com
Fri Dec 9 22:45:46 UTC 2016


Regarding my previous e-mail, I just realized maybe one way of dropping packets is if I replace the "^alert" keyword with "drop" in the rules.
However, is this the correct way?

Thanks,

Vieri



More information about the Oisf-users mailing list