I just counted, under each "rule" there are almost 40 individual items, I just took a quick screen shot to give everyone an idea of what was there. But they vary greatly.
So are you saying all the things in these lists are not really in effect, they are just things that have been tripped?
Very confusing to say the least if this is the case.
So if I just click on one of the items in these "lists" that will then whitelist that particular item?
Again just confusing I have 2 items under "Rule", with 40 sub items under each one of them.
When I click "whitelist an IDS rule" I get another "Rule" with 40 or so different sub items. Even when I click one of the sub items, nothing happens. I do not see that particular item listed, or added anywhere.
What am I missing?..This is what the doc says:
You can whitelist specific SNORT® signatures by clicking Whitelist an IDS rule. Any signatures for which matching traffic has been seen by the appliance will appear in the Select an Option drop-down so that you can select which signature or signatures you wish to whitelist.
So why do I have 2 "Rules"? maximum number of signatures in a rule? When I do click an item to whitelist I do not see it listed anywhere as being whitelisted? If I do delete both of these "rules". As the appliance starts to see attacks, will it just re-build the list again?
Sorry I just find it confusing the way it is presented.
Thank you again, really appreciate your time!