Automatically activate rules from certain categories and severities #14058
Replies: 5 comments 2 replies
-
Have you considered regex? |
Beta Was this translation helpful? Give feedback.
-
Hi, So if I disable a rule in detections manually because it triggers too many false positives it then gets activated again later on automatically if it matches the regex. Amy advice on how to do this? |
Beta Was this translation helpful? Give feedback.
-
Have you considered suppressing the individual rule? That way it can be enabled but won't actually generate alerts: |
Beta Was this translation helpful? Give feedback.
-
Hi Doug, |
Beta Was this translation helpful? Give feedback.
-
Hi Dough, |
Beta Was this translation helpful? Give feedback.
-
Hi,
is it possible to automatically activate eg. suricata rules from a certain category and severity of a feed once they are added?
Eg. if I wanted to automatically enable a new rule that was added to ET Free or ET Pro from the Exploit category with a severity of high - how would I do that?
I have some rules from the exploit category that I disabled on purpose. How can I avoid that they are activated again automatically?
Greetings
security-companion
Beta Was this translation helpful? Give feedback.
All reactions