Actions
Support #3045
closedHow limiting the number of alerts in the fast.log
Status:
Closed
Priority:
Normal
Assignee:
-
Affected Versions:
Label:
Description
Could you please tell me how it is possible to set up Suricata, that only one alert on one pcap-file got into the fast.log, even if the rule worked on it several times. The goal is to apply this setting to all rules at the same time.
Actions