[Oisf-users] Detection filters in global config
Davide Setti
d.setti at certego.net
Mon Mar 11 10:31:37 UTC 2019
Hi all,
We were reading about "detection filter" (
https://suricata.readthedocs.io/en/suricata-4.1.2/rules/thresholding.html#detection-filter)
to reduce the noise of some signatures (mainly mirai related).
We would like to avoid any in place changes to these rules.
Does "detection filter" works also in global threshold configuration?
If yes, this should be better explained in the docs
https://suricata.readthedocs.io/en/suricata-4.1.2/configuration/global-thresholds.html
.
Regards,
Davide
--
<http://www.certego.net/>
Davide Setti
R&D and Incident Response Team, Certego
<http://www.linkedin.com/company/certego> <http://twitter.com/Certego_IRT>
<http://github.com/certego> <http://www.youtube.com/CERTEGOsrl>
<http://plus.google.com/117641917176532015312>
Use of the information within this document constitutes acceptance for use
in an "as is" condition. There are no warranties with regard to this
information; Certego has verified the data as thoroughly as possible. Any
use of this information lies within the user's responsibility. In no event
shall Certego be liable for any consequences or damages, including direct,
indirect, incidental, consequential, loss of business profits or special
damages, arising out of or in connection with the use or spread of this
information.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openinfosecfoundation.org/pipermail/oisf-users/attachments/20190311/1401448a/attachment.html>
More information about the Oisf-users
mailing list