Snorby / snorby

Ruby On Rails Application For Network Security Monitoring
Other
1k stars 226 forks source link

How to exclude an IP address in snort for NST/Snorby #494

Open kriss332 opened 5 years ago

kriss332 commented 5 years ago

Hello all. I am using Snorby in NST. I want to get logs for all other IP addresses except one IP for a particular trigger. So I used ! exclamation before destination section (in downloaded.rules) and did a rule-update:-

alert any any -> !192.168.1.1 3389 .......contd.....

But I still get logs for 192.168.1.1 IP also alongwith other IPs. Any other place also should I touch?

Thanks