Intrusion Policy Suppression Types

Note that you can use intrusion event suppression alone or in any combination with rate-based attack prevention, the detection_filter keyword, and intrusion event thresholding.

Tip

You can add suppressions from within the packet view of an intrusion event. You can also access suppression settings by using the Alert Configuration column on the intrusion rules editor page (Policies > + Show more > Security policies > Intrusion Rules, click Snort 3 All Rules).