View and delete intrusion event thresholds
This task allows you to view existing threshold settings for intrusion rules and delete them when they are no longer appropriate for your system configuration.
To view or delete an existing threshold setting for a rule, use the Rules Details view to display the configured settings for a threshold and see if they are appropriate for your system. If they are not, you can add a new threshold to overwrite the existing values.
Procedure
Step 1 | Choose . |
Step 2 | Click Snort 3 All Rules tab. |
Step 3 | Choose the rule with a configured threshold as shown in the Alert Configuration column (the Alert Configuration column displays Threshold as a link for the rule). |
Step 4 | To remove the threshold for the rule, click Threshold link in the Alert Configuration column. |
Step 5 | Click Edit ( |
Step 6 | Click Threshold tab. |
Step 7 | Click Reset. |
Step 8 | Click Save. |
What to do next
Deploy configuration changes. See Deploy configuration changes.