Feature #122

Add support for event_filter/rate_filter

Added by Will Metcalf about 4 years ago. Updated almost 4 years ago.

Status:ClosedStart date:03/16/2010
Priority:NormalDue date:06/04/2010
Assignee:Pablo Rincon% Done:

0%

Category:-Estimated time:0.00 hour
Target version:0.9.2

Description

If thresholding is truly going away in a future version of snort we need to create task(s) to support at a minimum event_filter and optionally rate_filter.

History

#1 Updated by Will Metcalf about 4 years ago

the event_filter portion of this covered by task 130. I would add one clarification in that for the time being we should be able to use event_filter and threshold within the config file interchangeably. A task should be created for rate_filter.

#2 Updated by Will Metcalf about 4 years ago

from the snort manual... We currently don't have support for rate_filter

"Format
event_filter \
gen_id <gid>, sig_id <sid>, \
type <limit|threshold|both>, \
track <by_src|by_dst>, \
count <c>, seconds <s>
threshold \
gen_id <gid>, sig_id <sid>, \
type <limit|threshold|both>, \
track <by_src|by_dst>, \
count <c>, seconds <s>
threshold is an alias for event filter. Both formats are equivalent and support the options described below - all
are required. threshold is deprecated and will not be supported in future releases."

#3 Updated by Victor Julien almost 4 years ago

  • Due date changed from 05/16/2010 to 06/04/2010
  • Target version changed from 1.0.0 to 0.9.2
  • Estimated time set to 0.00

Will, what needs to be done for this?

#4 Updated by Victor Julien almost 4 years ago

It appears that we already have support for event_filter. Does it work like it should?

event_filter is indeed added although currently not working due to a bug see issue #172. We don't have support for rate_filter but maybe this can be moved to PII.

#5 Updated by Victor Julien almost 4 years ago

  • Status changed from New to Closed
  • Assignee changed from Victor Julien to Pablo Rincon

Patch by Pablo Rincon applied and pushed out.

Also available in: Atom PDF