I am trying to alert / ignore traffic from a list of blacklisted IP
I am using IP Reputation mentioned in docs
reputation-categories-file: /usr/local/etc/suricata/iprep/categories.txt default-reputation-path: /usr/local/etc/suricata/iprep reputation-files: - reputation.list
1,BadHosts,Known bad hosts
My Reputation List
I tried value 1 and 100 , it doesn’t affect , I can see this IP in eve.json
Here I want to know that do i need to create rules also using iprep ??
or what’s wrong