Project

General

Profile

Actions

Support #2431

closed

Change priority

Added by Roman Karpyuk about 6 years ago. Updated about 6 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Affected Versions:
Label:

Description

Dear colleagues,
can I change priority for set of rules or change type of action from "alert" to "drop" for all rules, for example, in file "mobile_malware.rules".
I use oinkmaster. Suricata 4.0.3.

Thanks.

Actions #1

Updated by Andreas Herz about 6 years ago

  • Assignee set to Anonymous
  • Target version set to Support
Actions #2

Updated by Victor Julien about 6 years ago

See http://suricata.readthedocs.io/en/latest/rule-management/oinkmaster.html

You'd add something like:

modifysid mobile_malware.rules "alert" | "drop" 
Actions #3

Updated by Roman Karpyuk about 6 years ago

I modify rules by sids every day but I haven't known that I can write like this "modifysid mobile_malware.rules ...".
Thanks alot for your hint.

Actions #4

Updated by Victor Julien about 6 years ago

  • Status changed from New to Closed
Actions

Also available in: Atom PDF