Software Secure Firewall Threat Defense
Platform Secure Firewall Threat Defense Virtual
Activity Onboard

Intrusion Detection and Prevention Get Started with Snort 3 Intrusion Policies Edit Snort 3 Intrusion Policies Rule Action Logging

Last updated: Jul 29, 2025

Rule Action Logging

From Firewall Management Center 7.2.0 onwards, in the Intrusion Events page, the event in the Inline Result column displays the same name as the IPS action applied to the rule, so that you can see the action that was applied on the traffic matching the rule.

For the IPS actions, the following table shows the events that are displayed in the Inline Result column of the Intrusion Events page and Action column for Intrusion Event Type in the Unified Events page.

IPS Action (Snort 2)

Inline Result - Firewall Management Center7.1.0 and earlier

Inline Result -Firewall Management Center 7.2.0 onwards

Alert

Pass

Alert

IPS Action for Snort 3

Inline Result - Firewall Management Center 7.1.0 and earlier

Inline Result -Firewall Management Center 7.2.0 onwards

Alert

Pass

Alert

Block

Dropped/Would Have Dropped/Partially Dropped

Block/Would Block/Partial Block

Drop

Dropped/Would have dropped

Drop/Would drop

Reject

Dropped/Would have dropped

Reject/Would reject

Rewrite

Allow

Rewrite


 
  • In case of a rule without the “Replace” option, the Rewrite action is displayed as Would Rewrite.

  • The Rewrite action would also be displayed as Would Rewrite if the "Replace" option is specified, but the IPS policy is in Detection mode or the device is in Inline-TAP/Passive mode.


 

In case of backward compatibility (Firewall Management Center 7.2.0 managing a Firewall Threat Defense 7.1.0 device), the events mentioned are applicable only to the Alert IPS action where Pass is displayed as Alert for events. For all the other actions, the events for Firewall Management Center 7.1.0 are applicable.