<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FireSIGHT suppression in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firesight-suppression/m-p/5279020#M1120499</link>
    <description>&lt;P&gt;Hello, please, how can I suppress the IDS alert in FMC?&lt;/P&gt;</description>
    <pubDate>Mon, 07 Apr 2025 14:55:14 GMT</pubDate>
    <dc:creator>anuoluwapo-bankole</dc:creator>
    <dc:date>2025-04-07T14:55:14Z</dc:date>
    <item>
      <title>FireSIGHT suppression</title>
      <link>https://community.cisco.com/t5/network-security/firesight-suppression/m-p/2917168#M1030059</link>
      <description>&lt;P&gt;When you add a suppression rule does it just remove the event from displaying or does it over ride the action too.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;SPAN&gt;You can suppress intrusion event notification for a rule or rules. When notification is suppressed for a rule, the rule triggers but events are not generated. You can set one or more suppressions for a rule. The first suppression listed has the highest priority. Note that when two suppressions conflict, the action of the first is carried out.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/firesight/541/user-guide/FireSIGHT-System-UserGuide-v5401/Intrusion-Tuning-Rules.html#53032" title="FireSIGHT System User Guide Version 5.4.1" target="_blank"&gt;FireSIGHT System User Guide Version 5.4.1&lt;/A&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If I add suppression for a rule that has a block condition will it still block, but just not alert? &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have a false positive that I want to rule out for a specific host, but don't want to disable the entire rule. &amp;nbsp;If the false positive triggers I dont want the traffic to be dropped AND I don't want to be alerted. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:04:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-suppression/m-p/2917168#M1030059</guid>
      <dc:creator>Justin bollinger</dc:creator>
      <dc:date>2019-03-12T13:04:10Z</dc:date>
    </item>
    <item>
      <title>In your case, suppression</title>
      <link>https://community.cisco.com/t5/network-security/firesight-suppression/m-p/2917169#M1030061</link>
      <description>&lt;P&gt;In your case, suppression will not trigger the rule to block. I'm guessing it is a documentation "bug", but once I suppress rule per "source", my false-positives go away.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2016 02:21:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-suppression/m-p/2917169#M1030061</guid>
      <dc:creator>Pavel Trinos</dc:creator>
      <dc:date>2016-07-12T02:21:41Z</dc:date>
    </item>
    <item>
      <title>Hello Team</title>
      <link>https://community.cisco.com/t5/network-security/firesight-suppression/m-p/2917170#M1030063</link>
      <description>&lt;P&gt;Hello Team&lt;/P&gt;
&lt;P&gt;By suppressing , the rule will still work but only difference is it wont generate any alerts for the same. To verify the false positive collect the pcap by clicking on packet download for that specific event in Intrusion events page and request TAC for false positive analysis.&lt;/P&gt;
&lt;P&gt;Rate if posts helps you.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Jetsy&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2016 05:26:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-suppression/m-p/2917170#M1030063</guid>
      <dc:creator>Jetsy Mathew</dc:creator>
      <dc:date>2016-07-12T05:26:27Z</dc:date>
    </item>
    <item>
      <title>The Suppression concept has</title>
      <link>https://community.cisco.com/t5/network-security/firesight-suppression/m-p/2917171#M1030067</link>
      <description>&lt;P&gt;The Suppression concept has had its misinterpretations over time. &amp;nbsp;The block will continue, but no alerts will be generated. basically, no notification. &amp;nbsp;If you intent is completely avoid an IP or group of IPs or segment, then you will have to modify the signature, (which will create a Local signature), and under this local signature, you can make all the changes you need by source or destination, same with ports, and other other parameters. &amp;nbsp;However, you will need to enable this signature, and disable the other. &amp;nbsp;And keep in mind that any updates on the original signature will not show in the modified signature,&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2016 19:14:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-suppression/m-p/2917171#M1030067</guid>
      <dc:creator>Ed Padilla Jr</dc:creator>
      <dc:date>2016-07-15T19:14:30Z</dc:date>
    </item>
    <item>
      <title>Thank you.  This is exactly</title>
      <link>https://community.cisco.com/t5/network-security/firesight-suppression/m-p/2917172#M1030071</link>
      <description>&lt;P&gt;Thank you. &amp;nbsp;This is exactly what I believed to be experiencing but wanted to confirm this was the expected behavior. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What I hear you guys saying is that you should only use the Suppression feature to tune out false positives of events that do not have a block action. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Enabling for an event with a block action would suppress the alert, but also block the packet, but you would not know that the event happened let alone that the event was blocked without a packet capture to confirm. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2016 19:49:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-suppression/m-p/2917172#M1030071</guid>
      <dc:creator>Justin bollinger</dc:creator>
      <dc:date>2016-07-15T19:49:19Z</dc:date>
    </item>
    <item>
      <title>Re: FireSIGHT suppression</title>
      <link>https://community.cisco.com/t5/network-security/firesight-suppression/m-p/5279020#M1120499</link>
      <description>&lt;P&gt;Hello, please, how can I suppress the IDS alert in FMC?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 14:55:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-suppression/m-p/5279020#M1120499</guid>
      <dc:creator>anuoluwapo-bankole</dc:creator>
      <dc:date>2025-04-07T14:55:14Z</dc:date>
    </item>
    <item>
      <title>Re: FireSIGHT suppression</title>
      <link>https://community.cisco.com/t5/network-security/firesight-suppression/m-p/5279034#M1120501</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1860765"&gt;@anuoluwapo-bankole&lt;/a&gt; please use one thread per question. You have already asked your question in a new thread. Don't jump on a 9-year old discussion.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 16:05:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-suppression/m-p/5279034#M1120501</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2025-04-07T16:05:39Z</dc:date>
    </item>
  </channel>
</rss>

