Hi there,
is there a work around to avoid Suricata displaying same alert within seconds from same IP?
Attached a better explanation about my question. It is displaying same alert 6 times between second 38 and second 39. I know it could be related to the different source/destination port but it would be helpful to be able to make some sort of filtering.
Thanks!
PS. XXX works very good for testing purposes
Suricata can limit the number of alerts generated by a rule using “thresholds”.
There’s multiple types of thresholds
- Per rule (requires rule modification)
- Global (requires
threshold.config
changes).
Global thresholds are discussed here: 10.2. Global-Thresholds — Suricata 7.0.0-rc2-dev documentation
Rule vs global thresholds are discussed here: 10.2. Global-Thresholds — Suricata 7.0.0-rc2-dev documentation
1 Like