View and Delete Intrusion Event Thresholds
To view or delete an existing threshold setting for a rule, use the Rules Details view to display the configured settings for a threshold and see if they are appropriate for your system. If they are not, you can add a new threshold to overwrite the existing values.
Procedure
1 |
Choose . |
2 |
Click Snort 3 All Rules tab. |
3 |
Choose the rule with a configured threshold as shown in the Alert Configuration column (the Alert Configuration column displays Threshold as a link for the rule). |
4 |
To remove the threshold for the rule, click Threshold link in the Alert Configuration column. |
5 |
Click Edit ( |
6 |
Click Threshold tab. |
7 |
Click Reset. |
8 |
Click Save. |
What to do next
Deploy configuration changes; see Deploy Configuration Changes.