<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Snort event filter]]></title><description><![CDATA[<p dir="auto">Snort 2.9.1 pkg v. 2.1.1  pfSense 2.0.1</p>
<p dir="auto">I'm getting flooded by alerts when running updates on my Linux box.</p>
<p dir="auto">Description<br />
ET POLICY GNU/Linux APT User-Agent Outbound likely related to package management  1:2013504:2</p>
<p dir="auto">I am trying to filter these event to only flag me once. When I read the manual and look at the examples under the suppress tab, I figured this command could work.</p>
<pre><code>event_filter gen_id 1, sig_id 2013504, type limit, track by_src, count 1, seconds 120
</code></pre>
<p dir="auto">I restarted the snort service but when I ran the update check from the Linux box and checked the alerts tab, I am still getting flooded by these warnings.</p>
<p dir="auto">Is my command syntax correct?</p>
]]></description><link>https://forum.netgate.com/topic/44542/snort-event-filter</link><generator>RSS for Node</generator><lastBuildDate>Thu, 23 Apr 2026 02:59:58 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/44542.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 02 May 2012 02:20:49 GMT</pubDate><ttl>60</ttl></channel></rss>