<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Event Action Filters on 2851 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/event-action-filters-on-2851/m-p/1132241#M78125</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is exactly what the 'event action filter' does. Whichever hosts you want to be ignored, add them using commas (as per my previous post),  then subtract the action 'Produce Alert'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 15 Dec 2008 19:06:49 GMT</pubDate>
    <dc:creator>Farrukh Haroon</dc:creator>
    <dc:date>2008-12-15T19:06:49Z</dc:date>
    <item>
      <title>Event Action Filters on 2851</title>
      <link>https://community.cisco.com/t5/network-security/event-action-filters-on-2851/m-p/1132238#M78120</link>
      <description>&lt;P&gt;Can I configure 'event action filters' from the CLI or do I have to use SDM?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:25:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/event-action-filters-on-2851/m-p/1132238#M78120</guid>
      <dc:creator>markbowman</dc:creator>
      <dc:date>2019-03-10T11:25:12Z</dc:date>
    </item>
    <item>
      <title>Re: Event Action Filters on 2851</title>
      <link>https://community.cisco.com/t5/network-security/event-action-filters-on-2851/m-p/1132239#M78122</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can change actions from the CLI on a signature/category basis, not so sure about removing actions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/ios/12_4t/12_4t11/ips_v5.html#wp1053954" target="_blank"&gt;http://www.cisco.com/en/US/docs/ios/12_4t/12_4t11/ips_v5.html#wp1053954&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 13 Dec 2008 14:09:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/event-action-filters-on-2851/m-p/1132239#M78122</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-12-13T14:09:22Z</dc:date>
    </item>
    <item>
      <title>Re: Event Action Filters on 2851</title>
      <link>https://community.cisco.com/t5/network-security/event-action-filters-on-2851/m-p/1132240#M78124</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I want to change the 'event action filters' where I can put in a certain ip address that should be ignored by the IPS.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Dec 2008 14:37:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/event-action-filters-on-2851/m-p/1132240#M78124</guid>
      <dc:creator>markbowman</dc:creator>
      <dc:date>2008-12-15T14:37:51Z</dc:date>
    </item>
    <item>
      <title>Re: Event Action Filters on 2851</title>
      <link>https://community.cisco.com/t5/network-security/event-action-filters-on-2851/m-p/1132241#M78125</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is exactly what the 'event action filter' does. Whichever hosts you want to be ignored, add them using commas (as per my previous post),  then subtract the action 'Produce Alert'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Dec 2008 19:06:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/event-action-filters-on-2851/m-p/1132241#M78125</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-12-15T19:06:49Z</dc:date>
    </item>
    <item>
      <title>Re: Event Action Filters on 2851</title>
      <link>https://community.cisco.com/t5/network-security/event-action-filters-on-2851/m-p/1132242#M78128</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm sorry, I didn't see in your last post where 'exactly' you add the ip address of the hosts from the command line. Can you show me the command to enter on the 2851 to ignore a particular host from a particular signature? Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Dec 2008 19:15:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/event-action-filters-on-2851/m-p/1132242#M78128</guid>
      <dc:creator>markbowman</dc:creator>
      <dc:date>2008-12-15T19:15:45Z</dc:date>
    </item>
    <item>
      <title>Re: Event Action Filters on 2851</title>
      <link>https://community.cisco.com/t5/network-security/event-action-filters-on-2851/m-p/1132243#M78130</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm sorry, I got confused with another thread I was working on. This is how you do it on an IPS sensor. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On IOS IPS, it used to be done using the following command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/ios/security/command/reference/sec_i2.html#wp1030715" target="_blank"&gt;http://www.cisco.com/en/US/docs/ios/security/command/reference/sec_i2.html#wp1030715&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ACL at the command was used to select which IPs that particular signature is valid for. However it seems that command has been removed in 12.4(11)T and I can't find any other way to do the same in the 5.x format introduced in 12.4(11)T.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Dec 2008 20:00:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/event-action-filters-on-2851/m-p/1132243#M78130</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-12-15T20:00:26Z</dc:date>
    </item>
  </channel>
</rss>

