Snort mailing list archives

Is there a notification on a rate_filter threshold being reached?


From: roni gur via Snort-sigs <snort-sigs () lists snort org>
Date: Sun, 21 Jun 2020 11:49:02 +0300

Hi,
I implemented a rate_filter threshold, but is there a way to generate an
alert for that rate_filter actually being reached, so I would know that I
need to look into that?

I should note that I'm using rate_filter primarily because I don't want to
track my events by src or dst, and hence use the by_rule option.

10x,
Roni.
_______________________________________________
Snort-sigs mailing list
Snort-sigs () lists snort org
https://lists.snort.org/mailman/listinfo/snort-sigs

Please visit http://blog.snort.org for the latest news about Snort!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a 
href=" https://snort.org/downloads/#rule-downloads";>emerging threats</a>!

Current thread: