<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VMS secmon and Trigger Packet in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vms-secmon-and-trigger-packet/m-p/790222#M86580</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check to see if you are still reporting Risk Ratings on your events in SecMon. We have had some senor updates break Risk Ratings. Re-importing the sensor in VMS fixes that problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 25 May 2007 15:44:31 GMT</pubDate>
    <dc:creator>rhermes</dc:creator>
    <dc:date>2007-05-25T15:44:31Z</dc:date>
    <item>
      <title>VMS secmon and Trigger Packet</title>
      <link>https://community.cisco.com/t5/network-security/vms-secmon-and-trigger-packet/m-p/790221#M86579</link>
      <description>&lt;P&gt;Right, in the network is a VMS Server 2.3sp2 and several 5.1.5E1s283.0 sensors. We have enabled the following commands on the sensors:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;overrides produce-verbose-alert &lt;/P&gt;&lt;P&gt;override-item-status Enabled&lt;/P&gt;&lt;P&gt;risk-rating-range 50&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SDEE events are received in VMS SecMon console. In the past with this enabled, when the Risk Rating was above 50 on any event received in the console,  this would produce a (verbose) trigger packet that would be viewable on the console by right clicking the event and the selecting tools/trigger packet. However it seams that this is not the case anymore. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could someone tell me if this function still works or has something changed that makes it not possible anymore?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:37:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vms-secmon-and-trigger-packet/m-p/790221#M86579</guid>
      <dc:creator>darin.marais</dc:creator>
      <dc:date>2019-03-10T10:37:45Z</dc:date>
    </item>
    <item>
      <title>Re: VMS secmon and Trigger Packet</title>
      <link>https://community.cisco.com/t5/network-security/vms-secmon-and-trigger-packet/m-p/790222#M86580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check to see if you are still reporting Risk Ratings on your events in SecMon. We have had some senor updates break Risk Ratings. Re-importing the sensor in VMS fixes that problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 May 2007 15:44:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vms-secmon-and-trigger-packet/m-p/790222#M86580</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2007-05-25T15:44:31Z</dc:date>
    </item>
    <item>
      <title>Re: VMS secmon and Trigger Packet</title>
      <link>https://community.cisco.com/t5/network-security/vms-secmon-and-trigger-packet/m-p/790223#M86581</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If I run show event on a sensor were I have enabled the commands:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;overrides produce-verbose-alert &lt;/P&gt;&lt;P&gt;override-item-status Enabled&lt;/P&gt;&lt;P&gt;risk-rating-range 50&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The event that is captured on the screen is as follows.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sensor# sh events&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;evIdsAlert: eventId=removed severity=high vendor=Cisco &lt;/P&gt;&lt;P&gt;  originator: &lt;/P&gt;&lt;P&gt;    hosted sensor&lt;/P&gt;&lt;P&gt;    appName: sensorApp&lt;/P&gt;&lt;P&gt;    appInstanceId: 5037&lt;/P&gt;&lt;P&gt;  time: 2007/05/30 08:05:57 2007/05/30 10:05:57 CET&lt;/P&gt;&lt;P&gt;  signature: description=Cursor/Icon File Format Buffer Overflow id=5442 version=S137 &lt;/P&gt;&lt;P&gt;    subsigId: 0&lt;/P&gt;&lt;P&gt;    sigDetails: Malicious ANI File&lt;/P&gt;&lt;P&gt;  interfaceGroup: &lt;/P&gt;&lt;P&gt;  vlan: 0&lt;/P&gt;&lt;P&gt;  participants: &lt;/P&gt;&lt;P&gt;    attacker: &lt;/P&gt;&lt;P&gt;      addr: locality=OUT removed&lt;/P&gt;&lt;P&gt;      port: 8080&lt;/P&gt;&lt;P&gt;    target: &lt;/P&gt;&lt;P&gt;      addr: locality=OUT removed&lt;/P&gt;&lt;P&gt;      port: 46531&lt;/P&gt;&lt;P&gt;  context: &lt;/P&gt;&lt;P&gt;    fromTarget: &lt;/P&gt;&lt;P&gt;text removed&lt;/P&gt;&lt;P&gt;    fromAttacker: &lt;/P&gt;&lt;P&gt;text removed&lt;/P&gt;&lt;P&gt;  riskRatingValue: 60&lt;/P&gt;&lt;P&gt;  interface: ge2_0&lt;/P&gt;&lt;P&gt;  protocol: tcp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The event includes the risk rating value. Is that what you mean?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the past the events collected were IDIOM events but now the are SDEE. Is there a difference as far as the triggered packets are concerned. In the past the event included a section called triggerPacket but I don?t see that anymore.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 May 2007 07:35:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vms-secmon-and-trigger-packet/m-p/790223#M86581</guid>
      <dc:creator>darin.marais</dc:creator>
      <dc:date>2007-05-30T07:35:28Z</dc:date>
    </item>
  </channel>
</rss>

