Support #3013
closed
Added by John Smith over 5 years ago.
Updated about 4 years ago.
Description
Does suricata detect the rules which action is "pass" at first;Then the rules with "alert"\"drop"?
And if two rules have the same action like 'alert',suricata will detect the rule which have a small id?
I just want to known the order that how suricat detect the rules.
Please give me some suggestions,thank you very much!
- Assignee changed from Victor Julien to OISF Dev
- Target version set to Support
Normally "pass" always comes before "alert" and "drop".
(for the order within alert rules itself I'm not sure if it can be predicted)
yes,if rules have a same proto,"pass" always comes before "alert" and "drop".
But when I use rules with different proto,it seems rules with "ip" have a first priority,then "tcp | udp",the last is "alproto".
So I want to known can I change the priority like "alproto","tcp | udp",the last is "ip".
If you have any good comments, thank you very much !
- Status changed from New to Feedback
I don't think there is a way to change that order, although I see that it might be relevant for the IPS mode where you want to drop traffic.
The file to look at is detect-engine-sigorder.c
- Status changed from Feedback to Closed
Also available in: Atom
PDF