Actions
Support #2431
closedChange priority
Status:
Closed
Priority:
Normal
Assignee:
-
Affected Versions:
Label:
Description
Dear colleagues,
can I change priority for set of rules or change type of action from "alert" to "drop" for all rules, for example, in file "mobile_malware.rules".
I use oinkmaster. Suricata 4.0.3.
Thanks.
Updated by Andreas Herz almost 7 years ago
- Assignee set to Anonymous
- Target version set to Support
Updated by Victor Julien almost 7 years ago
See http://suricata.readthedocs.io/en/latest/rule-management/oinkmaster.html
You'd add something like:
modifysid mobile_malware.rules "alert" | "drop"
Updated by Roman Karpyuk almost 7 years ago
I modify rules by sids every day but I haven't known that I can write like this "modifysid mobile_malware.rules ...".
Thanks alot for your hint.
Actions