For some reason, this rule is not being suppressed/disabled. I have double checked the gen_id, sig_id. Any thoughts on this?
Thanks
Shane
Hi Shane
Two things could be happening here if the rule is correctly disabled/suppressed.
Either it's a backlog from Barnyard2 still pushing old events to your database or the rule contains flowbit which re-enabled the rule.
Could you paste the rule here?
Regards,
Lysemose
--
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To post to this group, send email to securit...@googlegroups.com.
Visit this group at http://groups.google.com/group/security-onion.
For more options, visit https://groups.google.com/groups/opt_out.
Yes that's the issue, you have to enter 3:19187 to disable or suppress the rule. Snorby will always show 1 as gid no matter what.
/Lysemose