The rules detect order
Does suricata detect the rules which action is "pass" at first;Then the rules with "alert"\"drop"?
And if two rules have the same action like 'alert',suricata will detect the rule which have a small id?
I just want to known the order that how suricat detect the rules.
Please give me some suggestions,thank you very much!
Updated by John Smith over 3 years ago
yes,if rules have a same proto,"pass" always comes before "alert" and "drop".
But when I use rules with different proto,it seems rules with "ip" have a first priority,then "tcp | udp",the last is "alproto".
So I want to known can I change the priority like "alproto","tcp | udp",the last is "ip".
If you have any good comments, thank you very much !
Updated by Andreas Herz over 2 years ago
- Status changed from Feedback to Closed
Hi, we're closing this issue since there have been no further responses.
If you think this bug is still relevant, try to test it again with the
most recent version of suricata and reopen the issue. If you want to
improve the bug report please take a look at