View and Delete Intrusion Event Thresholds

To view or delete an existing threshold setting for a rule, use the Rules Details view to display the configured settings for a threshold and see if they are appropriate for your system. If they are not, you can add a new threshold to overwrite the existing values.

Procedure


Step 1

Choose Policies > + Show more > Security policies > Intrusion Rules.

Step 2

Click Snort 3 All Rules tab.

Step 3

Choose the rule with a configured threshold as shown in the Alert Configuration column (the Alert Configuration column displays Threshold as a link for the rule).

Step 4

To remove the threshold for the rule, click Threshold link in the Alert Configuration column.

Step 5

Click Edit (edit icon).

Step 6

Click Threshold tab.

Step 7

Click Reset.

Step 8

Click Save.


What to do next

Deploy configuration changes; see Deploy Configuration Changes.