Newbie to Suricata here.
In Suricata IDS mode. is it possible to block/drop/pass good traffic so it will not be seen in kibana?
drop ip any any <> any any (msg:“pass traffic for test”; sid:123;)
drop ip xxx any <> xxx any (msg:“pass traffic for test”; sid:123;)
These syntax did not work. i was still seeing traffic from that IP address. Please help
i also tried several commands such as supress, not, pass