HP-UX Host Intrusion Detection System Version 4.3 administrator guide

Table Of Contents
Figure 5-15 The Duplicate Alert Suppression Tab
Duplicate Alert Suppression Options
Following are the duplicate alert suppression options:
Duplicate Alert Suppression
Select or deselect the Duplicate Alert Suppression checkbox to enable or disable duplicate
alert suppression. By default, this property is enabled.
You can also set this property by editing the ids.cf file. Comment out the following entry
in the ids.cf file and set it to 1 (enabled) or 0 (disabled):
# suppression 0
Generate Suppression Report
Select the Generate Suppression Report checkbox if you want to receive an alert that contains
a summary of all the suppressed duplicate alerts for any given alert. When this checkbox is
selected, an alert summarizing all the duplicate alerts for any given alert is sent to the
alert.log file, the GUI, and the Response programs (located in the rt_response
directory).
NOTE: You receive an alert summarizing all the duplicate alerts only if at least one of the
criteria specified in the Suppression Count or Suppression Interval property is met.
If Duplicate Alert Suppression is selected, but Generate Suppression Report is not, no reports
summarizing duplicate alerts are generated. If you do not want to receive summary alerts,
deselect this checkbox. By default, this property is enabled.
You can also set this property by editing the ids.cf file. Comment out the following entry
in the ids.cf file and set it to 1 (enabled) or 0 (disabled).:
# suppression_report 0
Suppression Count
Use this property to suppress a specified number of duplicate alerts before the alert is issued
again. To configure the Suppression Count, set the Suppression Count property in the
Duplicate Alert Suppression tab. The default value of this property is 100. This means that
HIDS suppresses the next 100 duplicate alerts (for any given alert) within the specified
Suppression Interval.
Configuring Duplicate Alert Suppression 77