Ted Brand
unread,Jun 29, 2016, 1:32:22 PM6/29/16Sign in to reply to author
Sign in to forward
You do not have permission to delete messages in this group
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to security-onion
I am having a bit of an issue tuning some specific Suricata alerts in Security Onion. There are 3 alerts in particular, (Suricata UDPv4 invalid checksum, Suricata TCPv4 invalid Checksum, and Suricata IPv4 invalid checksum) that are firing about off at about a count of 100,000 over the course of 20 minutes and growing. I have tried numerous ways to turn off this alert but it still continues to fire.
The steps I have taken so far:
Disabled SID's in Pulled Pork's disablesid.conf
1:2200073
1:2200074
1:2200075
1:2200076
Turned off checksum stream validation in suricata.yaml
Commented out all of the checksum rules alerts in decoder-events.rules in regards to SURICATA invalid checksum.
After running a /usr/bin/rule-update and then a service nsm restart, these alerts are still coming into Squil/Squert.
My understanding of tuning Security Onion may be incorrect, but shouldn't turning off the alerting stop the alert from showing in these?