Feature Request: IPS Alerts Filtering

Started by csmall, June 08, 2017, 12:45:20 AM

Previous topic - Next topic
It would be nice to have some additional alert filtering options.

Right now you can do a basic search for something in the logs.

It would be great if we could filter more. Like show me all alerts maybe this dst ip and this action in this time frame or all alerts from this src ip that triggered this rule etc..

Also, is it possible to whitelist an ip in IPS? That would be cool.

Completely agree! Count me in on that!

Thank you.