<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hello khendrick512, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/custom-snort-rule-quot-eostore-failed-quot-cannot-commit-policy/m-p/2995072#M1018495</link>
    <description>&lt;P&gt;Hello&amp;nbsp;khendrick512,&lt;/P&gt;
&lt;P&gt;Make sure that its affecting only the custom rules or other local rules ?&lt;/P&gt;
&lt;P&gt;Could you please double check if the NAP actually commits even after showing the error.&lt;/P&gt;
&lt;P&gt;Regards&lt;BR /&gt;Jetsy&lt;/P&gt;</description>
    <pubDate>Thu, 27 Oct 2016 16:00:46 GMT</pubDate>
    <dc:creator>Jetsy Mathew</dc:creator>
    <dc:date>2016-10-27T16:00:46Z</dc:date>
    <item>
      <title>Custom Snort rule, "EOSTORE FAILED" - cannot commit policy changes</title>
      <link>https://community.cisco.com/t5/network-security/custom-snort-rule-quot-eostore-failed-quot-cannot-commit-policy/m-p/2995071#M1018493</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;In MC 6.0.1, I added two custom Snort rules (see end of post), turned these on to "generate events" in a few different Intrusion policies, and try to commit the changes, but it fails with the message "EOStore failed". &amp;nbsp;Has anyone else seen this?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The custom rules are related to the Mirai DDoS attacks:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;alert tcp $HOME_NET any -&amp;gt; $EXTERNAL_NET any (&amp;nbsp; msg: "Mirai C2 init"; content: "|00 00 00 01|"; offset:0; dsize: 4; sid:1; )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;alert tcp any any -&amp;gt; any 23 (&amp;nbsp; msg: "Mirai Telnet exploitation"; content: "/bin/busybox cat /proc/mounts|3B| /bin/busybox ECCHI"; sid:2; )&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:10:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/custom-snort-rule-quot-eostore-failed-quot-cannot-commit-policy/m-p/2995071#M1018493</guid>
      <dc:creator>khendrick512</dc:creator>
      <dc:date>2019-03-12T13:10:57Z</dc:date>
    </item>
    <item>
      <title>Hello khendrick512,</title>
      <link>https://community.cisco.com/t5/network-security/custom-snort-rule-quot-eostore-failed-quot-cannot-commit-policy/m-p/2995072#M1018495</link>
      <description>&lt;P&gt;Hello&amp;nbsp;khendrick512,&lt;/P&gt;
&lt;P&gt;Make sure that its affecting only the custom rules or other local rules ?&lt;/P&gt;
&lt;P&gt;Could you please double check if the NAP actually commits even after showing the error.&lt;/P&gt;
&lt;P&gt;Regards&lt;BR /&gt;Jetsy&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2016 16:00:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/custom-snort-rule-quot-eostore-failed-quot-cannot-commit-policy/m-p/2995072#M1018495</guid>
      <dc:creator>Jetsy Mathew</dc:creator>
      <dc:date>2016-10-27T16:00:46Z</dc:date>
    </item>
    <item>
      <title>It looks like you're right,</title>
      <link>https://community.cisco.com/t5/network-security/custom-snort-rule-quot-eostore-failed-quot-cannot-commit-policy/m-p/2995073#M1018498</link>
      <description>&lt;P&gt;It looks like you're right, though I'm still not sure what the real issue is. &amp;nbsp;I assumed the policy was not committing since the policy stays in edit mode and the error implies that the commit failed, but after I discard my edits and go into the policies, the custom rules are enabled to generate events.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2016 20:09:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/custom-snort-rule-quot-eostore-failed-quot-cannot-commit-policy/m-p/2995073#M1018498</guid>
      <dc:creator>khendrick512</dc:creator>
      <dc:date>2016-10-27T20:09:03Z</dc:date>
    </item>
  </channel>
</rss>

