Suricata Multi Select and Change

Started by Stefan, March 08, 2018, 03:20:30 PM

Previous topic - Next topic
Is there a way to select multiple rules and change them all, as a group, from Alert to Drop without having to change them one at a time? Such as, there are 302 netbios rules I want to change to drop. That will take an hour or more to do manually. Likewise with our groupings; malware, OSX, etc.



A better rules management system would be nice. I am sure it will come eventually. But from my perspective, it will probably require a total IDS GUI rewrite. Would be nice to know if something is in the works.