Suricata alert severity levels and how to verify that the maximum level that can be triggered by a test custom rule

Hi Jeff,

thank you for your reply.
So, the highest alert level is 1 and the lower is 4, right?

Now, if it is possible, I would like to ask you if there is a way to reduce the logs lines in eve and fast log files.

I know that I csan disable some rules or gorup fo rules, but I would like to have only one alert line per event and not a great number of identical lines in a few seconds.
In tthis way, I could send the log information to Wazuh and use Wazuh mail notification feature without flooding the mail server and my mail client :slight_smile:

Thank you,
Mauro