[Suricata] Would it be possible to add IPS blocked hosts to a custom block list?

Started by chropnsense, January 20, 2024, 09:54:03 AM

Previous topic - Next topic
Hi,

Case: Someone triggered a IDS rule on my Suricata list. Suricata blocks this connection.

=> Since we know the IP that got blocked, is there an (semi) easy way of adding this blocked IP to a custom block list that then can be used in firewall rules?

Thanks!