<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SubSig IDs - What is the differences in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/subsig-ids-what-is-the-differences/m-p/731012#M87164</link>
    <description>&lt;P&gt;What do the different SubSig IDs mean. Take SisID 5748 for example. There are SubSigs 0 - 3 for this SigID. I have started seeing quite a few of these in my event log. Most look to be SubSig ID 1 or 2 which are marked as informational where as the SubSig ID 0 is marked as low. I am trying to understand if this is an issue to / from my mail servers or not. Do I simply need to tune things further to filter out this? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way to run a report or something to see how long a specific Sig ID has been firing? &lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 10:32:01 GMT</pubDate>
    <dc:creator>bberry</dc:creator>
    <dc:date>2019-03-10T10:32:01Z</dc:date>
    <item>
      <title>SubSig IDs - What is the differences</title>
      <link>https://community.cisco.com/t5/network-security/subsig-ids-what-is-the-differences/m-p/731012#M87164</link>
      <description>&lt;P&gt;What do the different SubSig IDs mean. Take SisID 5748 for example. There are SubSigs 0 - 3 for this SigID. I have started seeing quite a few of these in my event log. Most look to be SubSig ID 1 or 2 which are marked as informational where as the SubSig ID 0 is marked as low. I am trying to understand if this is an issue to / from my mail servers or not. Do I simply need to tune things further to filter out this? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way to run a report or something to see how long a specific Sig ID has been firing? &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:32:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/subsig-ids-what-is-the-differences/m-p/731012#M87164</guid>
      <dc:creator>bberry</dc:creator>
      <dc:date>2019-03-10T10:32:01Z</dc:date>
    </item>
    <item>
      <title>Re: SubSig IDs - What is the differences</title>
      <link>https://community.cisco.com/t5/network-security/subsig-ids-what-is-the-differences/m-p/731013#M87165</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Signature 5748-0 is a meta engine signature.&lt;/P&gt;&lt;P&gt;Definition of Meta signature is here &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids13/idmguide/dmsigeng.htm#wp1040063" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids13/idmguide/dmsigeng.htm#wp1040063&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5748-0 should fire after detecting traffic that matches the sequence of the subsigs 1-5 as defined in 5748-0. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Subsigs 1-5 are meta component signatures, and by default configured to have no event action of their on, and should be left that way. This is because they are only looking for a very small subset of the main meta signature, and on their own could generate a lot of event alerts if set to produce alert.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have changed the default action, you should revert them back to default. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Depending on whether the event log storage has wrapped, you would be able to use the IDM for 5.x or SDM for 6.x using &amp;gt;monitoring&amp;gt;events to view if the signature has fired for the time setting you set.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this information helps you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Mar 2007 01:39:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/subsig-ids-what-is-the-differences/m-p/731013#M87165</guid>
      <dc:creator>edadios</dc:creator>
      <dc:date>2007-03-27T01:39:13Z</dc:date>
    </item>
  </channel>
</rss>

