  • We're running Suricata 4.0.12_2 on pfSense 2.4.3-RELEASE-p1. We've put the Suricata Alerts on the Dashboard, and we're getting a tremendous number of alerts that are not useful, such as for multicast and Discard protocol traffic from devices on a perimeter network. While we want Suricata to continue to manage such traffic as appropriate, we'd like to filter those messages out of not only the full log (and that filter is only temporary) but also from the Dashboard log. Is there any way to do that without suppressing or disabling the rule?

  • @bbcan177 Thank you! That's a great resource. I hope to find what I'm looking for right now in it (it's a long read), but I've already found a couple of things I wish I'd known before.

  • Have you made a pass list yet?

