Files
securityonion/salt/idstools/sorules/filer.rules
T
2021-02-19 11:01:15 -05:00

3 lines
218 B
Plaintext

# Start the filters at sid 1200000
# Example of filtering out google.com from being dns logged.
#config dns any any -> any any (dns.query; content:"google.com"; config: logging disable, type tx, scope tx; sid:1200000;)