View and Delete Intrusion Event Thresholds
To view or delete an existing threshold setting for a rule, use the Rules Details view to display the configured settings for a threshold and see if they are appropriate for your system. If they are not, you can add a new threshold to overwrite the existing values.
Procedure
Step 1 | Choose . |
Step 2 | Click Snort 3 All Rules tab. |
Step 3 | Choose the rule with a configured threshold as shown in the Alert Configuration column (the Alert Configuration column displays Threshold as a link for the rule). |
Step 4 | To remove the threshold for the rule, click Threshold link in the Alert Configuration column. |
Step 5 | Click Edit ( |
Step 6 | Click Threshold tab. |
Step 7 | Click Reset. |
Step 8 | Click Save. |
What to do next
Deploy configuration changes; see Deploy Configuration Changes.