Skip to content

Transfer SID disabled rules from Security Onion 1 to Security Onion 2 #5397

Locked Answered by dougburks
wompRS asked this question in General
Discussion options

You must be logged in to vote

In Security Onion 16.04, you would have disabled rules in /etc/nsm/pulledpork/disablesid.conf:
https://docs.securityonion.net/en/16.04/alerts.html#disable-the-sid

In Security Onion 2, you can disable rules via the so-rule command or in the minion pillar file:
https://docs.securityonion.net/en/2.3/managing-alerts.html#disable-the-sid

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by dougburks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants