Set suppression for an intrusion rule in Snort 3

This task allows you to configure one or more suppressions for a rule in your intrusion policy to reduce false positives and focus on relevant security events.

You can set one or more suppressions for a rule in your intrusion policy.

Before you begin

Ensure you create the required network objects to be added for source or destination suppression.

Follow these steps to set suppression for an intrusion rule in Snort 3:

Procedure


Step 1

Choose Policies > + Show more > Security policies > Intrusion Rules.

Step 2

Click Snort 3 All Rules tab.

Step 3

Click the None link in the Alert Configuration column for the intrusion rule.

Step 4

Click Edit (edit icon).

Step 5

From the Suppressions tab, click the add icon Add (add icon) next to any of these options:

  • Choose Source Networks to suppress events generated by packets originating from a specified source IP address.

  • Choose Destination Networks to suppress events generated by packets going to a specified destination IP address.

Step 6

Select any of the preset networks in the Network drop-down list.

Step 7

Click Save.

Step 8

(Optional) Repeat steps 5, 6, and 7 if needed.

Step 9

Click Save in the Alert Configuration window.


What to do next

Deploy configuration changes. See Deploy configuration changes.