<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPS-4240-K9 IDM 6.2 Monitoring Events issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-4240-k9-idm-6-2-monitoring-events-issue/m-p/1913743#M55322</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For signatures firing a lot, you can use IPS CLI command "show stats virtual-sensor" &lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;"show statistics virtual-sensor | be SigEvent count"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sawan Gupta&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 10 May 2012 08:52:00 GMT</pubDate>
    <dc:creator>sawgupta</dc:creator>
    <dc:date>2012-05-10T08:52:00Z</dc:date>
    <item>
      <title>IPS-4240-K9 IDM 6.2 Monitoring Events issue</title>
      <link>https://community.cisco.com/t5/network-security/ips-4240-k9-idm-6-2-monitoring-events-issue/m-p/1913740#M55319</link>
      <description>&lt;P&gt;hi, everyone&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i've noticed one tangled fact on idm monitoring events dashboard. it doesn't show alerts, which i notice on main page home/netwrok security health sensor cyrcle. In the past 5 minutes sensor show for example 10 red alerts, but when i switch on event dashboard - there are nothing on this table.....&lt;/P&gt;&lt;P&gt;several days ago i saw some periodical alerts about&lt;STRONG&gt; 4003&lt;/STRONG&gt; signature - nmap udp sweep. it was happening during week, and i think that quaintity of real tine alerts on sensor health cyrcle and on events table were the same.&lt;/P&gt;&lt;P&gt;only that i'm noticing now,&lt;STRONG&gt; 3041&lt;/STRONG&gt; signature and some times&lt;STRONG&gt; errorMessage: - the event store wrapped around [IdsEventStore::writeEvent(), index = 19531]&amp;nbsp; name=errWarning&amp;nbsp; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;i've read about this error some notes,but don't understand what should i change for viewing real-time alerts and &lt;STRONG&gt;4003&lt;/STRONG&gt; signature (when idm works correct, it was the main attack). practically all confoguration on default values. ips works in promiscious mode&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for any help and advices&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:40:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-4240-k9-idm-6-2-monitoring-events-issue/m-p/1913740#M55319</guid>
      <dc:creator>Ruslan Mansurau</dc:creator>
      <dc:date>2019-03-10T12:40:05Z</dc:date>
    </item>
    <item>
      <title>IPS-4240-K9 IDM 6.2 Monitoring Events issue</title>
      <link>https://community.cisco.com/t5/network-security/ips-4240-k9-idm-6-2-monitoring-events-issue/m-p/1913741#M55320</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Regarding the message "&lt;STRONG&gt;errorMessage: - the event store wrapped around "&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Events are stored in a circular buffer. Once the buffer if full, we would simply overwrite the oldest event. If you are seeing multiple such messages, it means that the number of events is really high. You might want to set&lt;STRONG&gt; Alert Frequency &amp;gt; Summary Mode &lt;/STRONG&gt;for the signatures which are firing a lot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Refer to the following link to configure Summary Mode:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/sw/secursw/ps2113/products_tech_note09186a0080838bcf.shtml#IDM"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2113/products_tech_note09186a0080838bcf.shtml#IDM&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sawan Gupta&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 06 May 2012 11:05:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-4240-k9-idm-6-2-monitoring-events-issue/m-p/1913741#M55320</guid>
      <dc:creator>sawgupta</dc:creator>
      <dc:date>2012-05-06T11:05:00Z</dc:date>
    </item>
    <item>
      <title>IPS-4240-K9 IDM 6.2 Monitoring Events issue</title>
      <link>https://community.cisco.com/t5/network-security/ips-4240-k9-idm-6-2-monitoring-events-issue/m-p/1913742#M55321</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN __jive_emoticon_name="confused" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt; one more question - how can i reveal definite signatures which are firing a lot? because this message appears in all tables which I choose (show monitoring events dashboard - for example only high or only medium or only low notifications)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and could you give me pieces of&amp;nbsp; advice for primary configuring ips (any books, notes, examples), please? i've explored several on cisco.com, but only what i've found is general opportunities of ips&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; p.s. for beginners in security)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2012 06:31:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-4240-k9-idm-6-2-monitoring-events-issue/m-p/1913742#M55321</guid>
      <dc:creator>Ruslan Mansurau</dc:creator>
      <dc:date>2012-05-10T06:31:34Z</dc:date>
    </item>
    <item>
      <title>IPS-4240-K9 IDM 6.2 Monitoring Events issue</title>
      <link>https://community.cisco.com/t5/network-security/ips-4240-k9-idm-6-2-monitoring-events-issue/m-p/1913743#M55322</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For signatures firing a lot, you can use IPS CLI command "show stats virtual-sensor" &lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;"show statistics virtual-sensor | be SigEvent count"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sawan Gupta&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2012 08:52:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-4240-k9-idm-6-2-monitoring-events-issue/m-p/1913743#M55322</guid>
      <dc:creator>sawgupta</dc:creator>
      <dc:date>2012-05-10T08:52:00Z</dc:date>
    </item>
    <item>
      <title>Re: IPS-4240-K9 IDM 6.2 Monitoring Events issue</title>
      <link>https://community.cisco.com/t5/network-security/ips-4240-k9-idm-6-2-monitoring-events-issue/m-p/1913744#M55323</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks one more time&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ok, i've found big quantity in some signature, but this signature hasn't changed for producing alerts (by default). so can it make this wrapping error? or i should find those signature which produces alerts to monitoring events dashboard and after that change state for appearing this alert from Fire all to Summarize as you said at the first answer?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2012 11:40:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-4240-k9-idm-6-2-monitoring-events-issue/m-p/1913744#M55323</guid>
      <dc:creator>Ruslan Mansurau</dc:creator>
      <dc:date>2012-05-10T11:40:50Z</dc:date>
    </item>
    <item>
      <title>Re: IPS-4240-K9 IDM 6.2 Monitoring Events issue</title>
      <link>https://community.cisco.com/t5/network-security/ips-4240-k9-idm-6-2-monitoring-events-issue/m-p/1913745#M55324</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can verify the events using command "show events"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- If it is a false positve, then you might want to report it to Cisco TAC.&lt;/P&gt;&lt;P&gt;- Or summarize the signature event.&lt;/P&gt;&lt;P&gt;- If the signature is not relevant then you may retire and disable it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sawan Gupta&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2012 12:57:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-4240-k9-idm-6-2-monitoring-events-issue/m-p/1913745#M55324</guid>
      <dc:creator>sawgupta</dc:creator>
      <dc:date>2012-05-10T12:57:44Z</dc:date>
    </item>
  </channel>
</rss>

