<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Event Action Filter not working in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/event-action-filter-not-working/m-p/1318112#M68356</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, but, for example, if you activate action "produce verbose alert" in signature but check the action to substract "produce alert" or don't check any filters must not work.&lt;/P&gt;&lt;P&gt;Post the config fragments of signature and of filters here.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 28 Oct 2009 13:34:20 GMT</pubDate>
    <dc:creator>andrey.dugin</dc:creator>
    <dc:date>2009-10-28T13:34:20Z</dc:date>
    <item>
      <title>Event Action Filter not working</title>
      <link>https://community.cisco.com/t5/network-security/event-action-filter-not-working/m-p/1318107#M68351</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are running an IDSM-2 with 7.0(1)E3 and 2 virtual sensors.&lt;/P&gt;&lt;P&gt;I want to filter alarms from sig 2004 for a monitoring server.&lt;/P&gt;&lt;P&gt;When adding an event action filter, it still sends alarms. Bug?? Is there another way to filter the alarms for a specific host?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;/Ola&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:48:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/event-action-filter-not-working/m-p/1318107#M68351</guid>
      <dc:creator>ola</dc:creator>
      <dc:date>2019-03-10T11:48:48Z</dc:date>
    </item>
    <item>
      <title>Re: Event Action Filter not working</title>
      <link>https://community.cisco.com/t5/network-security/event-action-filter-not-working/m-p/1318108#M68352</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Event action rules set is assigned to virtual sensor. If you have assigned event action rules set to one virtual sensor and another rules to another vs:&lt;/P&gt;&lt;P&gt;rules0 - vs0&lt;/P&gt;&lt;P&gt;rules1 - vs1&lt;/P&gt;&lt;P&gt;you must create filter on every rules set to substract some action on whole sensor.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Oct 2009 09:42:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/event-action-filter-not-working/m-p/1318108#M68352</guid>
      <dc:creator>andrey.dugin</dc:creator>
      <dc:date>2009-10-28T09:42:37Z</dc:date>
    </item>
    <item>
      <title>Re: Event Action Filter not working</title>
      <link>https://community.cisco.com/t5/network-security/event-action-filter-not-working/m-p/1318109#M68353</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to apply the same filter to both sensors, same result, I still get the alarms.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Oct 2009 09:52:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/event-action-filter-not-working/m-p/1318109#M68353</guid>
      <dc:creator>ola</dc:creator>
      <dc:date>2009-10-28T09:52:01Z</dc:date>
    </item>
    <item>
      <title>Re: Event Action Filter not working</title>
      <link>https://community.cisco.com/t5/network-security/event-action-filter-not-working/m-p/1318110#M68354</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sig 2004/0 ICMP Echo Request is disabled by default.&lt;/P&gt;&lt;P&gt;Did you activate the same action in signature action and substract action in the filter?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Oct 2009 10:08:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/event-action-filter-not-working/m-p/1318110#M68354</guid>
      <dc:creator>andrey.dugin</dc:creator>
      <dc:date>2009-10-28T10:08:58Z</dc:date>
    </item>
    <item>
      <title>Re: Event Action Filter not working</title>
      <link>https://community.cisco.com/t5/network-security/event-action-filter-not-working/m-p/1318111#M68355</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I enabled the signature in one sensor and want to filter alarms for one specific ip address.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Oct 2009 10:32:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/event-action-filter-not-working/m-p/1318111#M68355</guid>
      <dc:creator>ola</dc:creator>
      <dc:date>2009-10-28T10:32:17Z</dc:date>
    </item>
    <item>
      <title>Re: Event Action Filter not working</title>
      <link>https://community.cisco.com/t5/network-security/event-action-filter-not-working/m-p/1318112#M68356</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, but, for example, if you activate action "produce verbose alert" in signature but check the action to substract "produce alert" or don't check any filters must not work.&lt;/P&gt;&lt;P&gt;Post the config fragments of signature and of filters here.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Oct 2009 13:34:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/event-action-filter-not-working/m-p/1318112#M68356</guid>
      <dc:creator>andrey.dugin</dc:creator>
      <dc:date>2009-10-28T13:34:20Z</dc:date>
    </item>
    <item>
      <title>Re: Event Action Filter not working</title>
      <link>https://community.cisco.com/t5/network-security/event-action-filter-not-working/m-p/1318113#M68357</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I removed produce alert on the signature.&lt;/P&gt;&lt;P&gt;Enabled it again and then reapplied the filter, and for some reason, it now works. Anyway, thanks for your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Oct 2009 07:56:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/event-action-filter-not-working/m-p/1318113#M68357</guid>
      <dc:creator>ola</dc:creator>
      <dc:date>2009-10-29T07:56:27Z</dc:date>
    </item>
  </channel>
</rss>

