"Event Message: ET DELETED" Meaning?

883 views
Skip to first unread message

SpaceVirus

unread,
Dec 21, 2016, 1:30:45 PM12/21/16
to security-onion
Hey guys. I was just curious as to what "ET DELETED" means under emerging threats.

Are these outdated rules that can be ignored?

Image attached.

Thanks in advance for the help guys.
ET_DELETED.PNG

Wes Lambert

unread,
Dec 21, 2016, 1:37:10 PM12/21/16
to securit...@googlegroups.com

SpaceVirus,

In short, yes.  You may want to see the following:

https://www.snort.org/rules_explanation

Thanks,
Wes


--
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onion+unsubscribe@googlegroups.com.
To post to this group, send email to security-onion@googlegroups.com.
Visit this group at https://groups.google.com/group/security-onion.
For more options, visit https://groups.google.com/d/optout.

SpaceVirus

unread,
Dec 21, 2016, 2:07:43 PM12/21/16
to security-onion
Thanks very much Wes. You're the man.

James Ebersold

unread,
Mar 29, 2018, 3:54:55 PM3/29/18
to security-onion
Any thought on why if the event is obsolete it remains as a rule? We want to quiet noise and it seems to qualify as noise.

Doug Burks

unread,
Apr 8, 2018, 8:08:23 AM4/8/18
to securit...@googlegroups.com
Hi James,

Please feel free to disable any rules that qualify as noise in your environment:

On Thu, Mar 29, 2018 at 3:52 PM, James Ebersold <jjebe...@gmail.com> wrote:
Any thought on why if the event is obsolete it remains as a rule?  We want to quiet noise and it seems to qualify as noise.
--
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onion+unsubscribe@googlegroups.com.
To post to this group, send email to security-onion@googlegroups.com.
Visit this group at https://groups.google.com/group/security-onion.
For more options, visit https://groups.google.com/d/optout.



--
Doug Burks

James Ebersold

unread,
Apr 30, 2018, 2:41:37 PM4/30/18
to security-onion
On Sunday, April 8, 2018 at 8:08:23 AM UTC-4, Doug Burks wrote:
> Hi James,
>
>
> Please feel free to disable any rules that qualify as noise in your environment:
> https://github.com/Security-Onion-Solutions/security-onion/wiki/ManagingAlerts#disable-the-sid
>
>
>
> On Thu, Mar 29, 2018 at 3:52 PM, James Ebersold <jjebe...@gmail.com> wrote:
> Any thought on why if the event is obsolete it remains as a rule?  We want to quiet noise and it seems to qualify as noise.
>
>
>
>
>
> --
>
> Follow Security Onion on Twitter!
>
> https://twitter.com/securityonion
>
> ---
>
> You received this message because you are subscribed to the Google Groups "security-onion" group.
>
> To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
>
> To post to this group, send email to securit...@googlegroups.com.
>
> Visit this group at https://groups.google.com/group/security-onion.
>
> For more options, visit https://groups.google.com/d/optout.
>
>
>
>
>
> --
>
> Doug Burks

My question was not really about how to remove a rule but why obsolete rules remain.

Wes Lambert

unread,
Apr 30, 2018, 9:17:09 PM4/30/18
to securit...@googlegroups.com
James,

You may find a more thorough explanation on the ET mailing list:


Thanks,
Wes

To unsubscribe from this group and stop receiving emails from it, send an email to security-onion+unsubscribe@googlegroups.com.
To post to this group, send email to security-onion@googlegroups.com.
Reply all
Reply to author
Forward
0 new messages