snort 3

Albert O'Balsam via Snort-users <[email protected]>
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <[email protected]>
Hi,

I wonder if anyone can help me.

I'm experimenting with the suppression functionality of snort 3. I've
googled, read the documentation multiple times, and have a configuration
that is accepted by snort, but it doesn't seem to work they way I'd expect
it to.

So for example, if I setup the supress section to look like the following,
it works fine. No alerts of this type are generated.

suppress =
{
    { gid = 122, sid = 1 }
}

But if I add an IP source, the configuration doesn't generate any errors,
but nothing is supressed.

suppress =
{
    { gid = 122, sid = 1, track = by_src, ip = '1.2.3.4' }
}

Any idea what I am doing wrong?

Also, as a feature request, would it be useful to be able to supress based
on a dynamic list, say for example based on the output of a DNS request
(that could be cached and periodically updated for efficiency)?

TIA,
Albert O'Balsam

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.