Skip to content

Add in detections a pre-filter that selects all rules that are not ok #13284

Locked Answered by defensivedepth
sleepingbel asked this question in Ideas
Discussion options

You must be logged in to vote

Ok, you need to remove - re:DNS Query from /opt/so/saltstack/local/pillar/idstools/soc_idstools.sls , run sudo salt-call state.apply idstools and then sync suricata in Detections. Give it an hour or so and then lets go from there.

Replies: 2 comments 6 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
6 replies
@sleepingbel
Comment options

@defensivedepth
Comment options

@sleepingbel
Comment options

@defensivedepth
Comment options

Answer selected by sleepingbel
@sleepingbel
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Ideas
Labels
None yet
2 participants