Project

General

Profile

Actions

Feature #1137

closed

Support IP lists in threshold.config

Added by Duane Howard over 8 years ago. Updated over 7 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

Snort currently supports lists like:
suppress gen_id 1, sig_id 12345, track by_src, ip [10.1.1.1,10.1.2.3,192.168.1.9]

The same requires multiple rules in Suricata:
suppress gen_id 1, sig_id 12345, track by_src, ip 10.1.1.1
suppress gen_id 1, sig_id 12345, track by_src, ip 10.1.2.3
suppress gen_id 1, sig_id 12345, track by_src, ip 192.168.1.9

Actions #1

Updated by Victor Julien over 8 years ago

  • Target version set to TBD
Actions #2

Updated by Duane Howard almost 8 years ago

Was this considered for 2.1 ?

Actions #3

Updated by Duane Howard over 7 years ago

Friendly ping?

Actions #4

Updated by Victor Julien over 7 years ago

  • Status changed from New to Closed
  • Assignee set to Victor Julien
  • Target version changed from TBD to 3.0RC1
  • % Done changed from 0 to 100
Actions

Also available in: Atom PDF