Delete rule groups
Delete rule groups to remove unwanted or obsolete intrusion detection rules from your system configuration and maintain an organized rule structure.
Before deleting a rule group, you must exclude it from all intrusion policies and disable all rules within the group to prevent system conflicts.
Before you begin
Exclude the rule group you want to delete from all intrusion policies where you have included it. For steps on excluding a rule group from an intrusion policy, see Edit Snort 3 Intrusion Policies.
Follow these steps to delete rule groups:
Procedure
Step 1 | Choose . |
Step 2 | Click Snort 3 All Rules tab. |
Step 3 | Expand Local Rules in the left pane. |
Step 4 | Select the rule group to be deleted. |
Step 5 | Ensure the rule action for all the rules in the group is set to Disable before proceeding. If the rule action for any of the rules is anything other than Disable, then you cannot delete the rule group. If required, follow the steps below to disable the rule action for all the rules:
|
Step 6 | Click the Delete ( |
Step 7 | Click OK in the Delete Rule Group pop-up window. |
What to do next
Deploy configuration changes. See Deploy configuration changes.
