<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AMP Alert Cutoff in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/amp-alert-cutoff/m-p/3085602#M1014928</link>
    <description>&lt;P&gt;We receive AMP alerts frequently for malware attached to e-mail. &amp;nbsp;We aren't concerned so much about that malware because our filter is excellent at dropping those messages. &amp;nbsp;However, the alerts don't tell us enough information because they're cut off. &amp;nbsp;This is what we get:&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"&gt;&amp;lt;*- Network Based Retrospective at Tue Aug&amp;nbsp; 1 16:13:57 2017 UTC -*&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"&gt;Sha256: f0d4ec15201ff5115cefeb3f29d523506fdd641807c0660689a9259f11bdc347&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"&gt;Disposition: Malware&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"&gt;Threat name: N/A&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"&gt;&amp;lt;*- Network Based Retrospective&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"&gt;From "&amp;lt;hostname&amp;gt;" at Tue&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;It cuts off after the day of the week. &amp;nbsp;It'd be nice if we could get the rest of the information in the e-mail so we can quickly determine if we should be concerned or not.&lt;/P&gt;
&lt;P&gt;Is this a known issue? &amp;nbsp;Any suggestions on fixing it? &amp;nbsp;We're on FMC 6.0.1.3, build 1054.&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 13:28:42 GMT</pubDate>
    <dc:creator>Trevor Walraven</dc:creator>
    <dc:date>2019-03-12T13:28:42Z</dc:date>
    <item>
      <title>AMP Alert Cutoff</title>
      <link>https://community.cisco.com/t5/network-security/amp-alert-cutoff/m-p/3085602#M1014928</link>
      <description>&lt;P&gt;We receive AMP alerts frequently for malware attached to e-mail. &amp;nbsp;We aren't concerned so much about that malware because our filter is excellent at dropping those messages. &amp;nbsp;However, the alerts don't tell us enough information because they're cut off. &amp;nbsp;This is what we get:&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"&gt;&amp;lt;*- Network Based Retrospective at Tue Aug&amp;nbsp; 1 16:13:57 2017 UTC -*&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"&gt;Sha256: f0d4ec15201ff5115cefeb3f29d523506fdd641807c0660689a9259f11bdc347&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"&gt;Disposition: Malware&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"&gt;Threat name: N/A&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"&gt;&amp;lt;*- Network Based Retrospective&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"&gt;From "&amp;lt;hostname&amp;gt;" at Tue&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;It cuts off after the day of the week. &amp;nbsp;It'd be nice if we could get the rest of the information in the e-mail so we can quickly determine if we should be concerned or not.&lt;/P&gt;
&lt;P&gt;Is this a known issue? &amp;nbsp;Any suggestions on fixing it? &amp;nbsp;We're on FMC 6.0.1.3, build 1054.&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:28:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/amp-alert-cutoff/m-p/3085602#M1014928</guid>
      <dc:creator>Trevor Walraven</dc:creator>
      <dc:date>2019-03-12T13:28:42Z</dc:date>
    </item>
    <item>
      <title>Hi Trevor,</title>
      <link>https://community.cisco.com/t5/network-security/amp-alert-cutoff/m-p/3085603#M1014951</link>
      <description>&lt;P&gt;Hi Trevor,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This new retrospective malware event represents a disposition change for all files detected in the last week that have the same SHA-256 hash value. For that reason, these events contain limited information: the date and time the Firepower Management Center was notified of the disposition change, the new disposition, the SHA-256 hash value of the file, and the threat name. They do not contain IP addresses or other contextual information.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;That's something known. Let us know for any query.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Dv&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 14:43:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/amp-alert-cutoff/m-p/3085603#M1014951</guid>
      <dc:creator>Dinesh Verma</dc:creator>
      <dc:date>2017-08-03T14:43:18Z</dc:date>
    </item>
  </channel>
</rss>

