View and Delete Suppression Conditions

You may want to view or delete an existing suppression condition. For example, you can suppress event notification for packets originating from a mail server IP address because the mail server normally transmits packets that look like exploits. If you then decommission that mail server and reassign the IP address to another host, you should delete the suppression conditions for that source IP address.

Procedure

1

Choose Objects > Intrusion Rules.

2

Click Snort 3 All Rules tab.

3

Choose the rule for which you want to view or delete suppressions.

4

Click Suppression in the Alert Configuration column.

5

Click Edit (edit icon).

6

Click Suppressions tab.

7

Remove the suppression by clicking Clear (clear icon) next to the suppression.

8

Click Save.

What to do next

Deploy configuration changes; see Deploy Configuration Changes.