Actions
Feature #8250
openrules: distinct ip counting logic
Effort:
low
Difficulty:
Label:
Description
In continuous to this ticket - https://redmine.openinfosecfoundation.org/issues/7928.
Implementing now unique_on options for src_ip and dst_ip.
Example for host scan rule:alert tcp any any -> any any (msg:"Potential TCP SYN Scan Detected"; flags:S; threshold:type both, track by_src, count 50, seconds 60, unique_on dst_ip; classtype:network-scan; sid:1000001; rev:1;)
Actions