Is it possible to modify what alerts get generated or suppressed based on the host profile? For example, if my DMZ Host is Windows then do not generate alerts specific to Linux.
check out correlation rules. Very powerful
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: