I have another semi-odd request that I haven't been able to get answers for elsewhere, so here goes. This is also another one that may need to end in RFE - or just be dropped as non-essential.
Has anyone found a clean way to reset the hit count of an individual rule without losing the UID? I know we can copy/paste/delete to get a [mostly] identical copy of a rule with no hits, but the replacement will have a new UID - and mess with logging/reporting.
I know believe the counts are stored within both kernel tables and files, but before I go hacking around I figured I'd see if someone already has.
-E