Delete custom rules

Delete custom rules that are no longer needed from your intrusion rule configuration to maintain an organized and efficient rule set.

Use this procedure when you need to remove custom rules from the Local Rules section in the Snort 3 All Rules interface. Before deletion, all rules must be disabled to prevent configuration conflicts.

Procedure


Step 1

Choose Policies > + Show more > Security policies > Intrusion Rules.

Step 2

Click Snort 3 All Rules tab.

Step 3

Expand Local Rules in the left pane.

Step 4

Check the check boxes of the rules you want to delete.

Step 5

Ensure that the rule action for all the rules that you select is Disable.

If required, follow these steps to disable the rule action for multiple selected rules:

  1. From the Rule Actions drop-down box, select Per Intrusion Policy.

  2. Select All Policies radio button.

  3. Select Disable from the Select Override state drop-down list.

  4. Click Save.

  5. Check the check boxes of the rules you want to delete.

Step 6

From the Rule Actions drop-down list, select Delete.

Step 7

Click Delete in the Delete Rules pop-up window.


What to do next

Deploy configuration changes. See Deploy configuration changes.