Snort alert only on priority 1
-
Is there any way to make Snort generate alerts only for rules with priority 1?
-
@hehob60672 said in Snort alert only on priority 1:
Is there any way to make Snort generate alerts only for rules with priority 1?
No, unfortunately the PRIORITY field is not an option for alert suppression/thresholding. If the only rules you want to even inspect traffic are those marked as PRIORITY 1, then you could perhaps use the pattern matching features on the SID MGMT tab to select only rules matching that criteria to enable.