<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: help need on the event count parameter of signatures in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/help-need-on-the-event-count-parameter-of-signatures/m-p/647113#M87937</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;mm  ..  good that you mentioned because the decription on the CCSP book is not very clear &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 27 Dec 2006 01:37:19 GMT</pubDate>
    <dc:creator>Fernando_Meza</dc:creator>
    <dc:date>2006-12-27T01:37:19Z</dc:date>
    <item>
      <title>help need on the event count parameter of signatures</title>
      <link>https://community.cisco.com/t5/network-security/help-need-on-the-event-count-parameter-of-signatures/m-p/647110#M87934</link>
      <description>&lt;P&gt;hi all i have a little confusion abt the event count parameter in the signatures. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i am not sure whether this parameter is for firing the signatures or for writing the events to the event store. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;by default the event count is set to 1. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if i set the event count to 5 for a particular signature. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;say for icmp echo request. if i set the signature event count to 5 within 10 seconds interval. and the signature action is to deny the packet inline. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then when the first icmp echo request is send will the signature be fired i mean will the packet be dropped. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or the packet will be dropped only if 5 icmp echo requests are send within 10 seconds. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can someone pls clear my doubt. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sebastan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:23:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-need-on-the-event-count-parameter-of-signatures/m-p/647110#M87934</guid>
      <dc:creator>sebastan_bach</dc:creator>
      <dc:date>2019-03-10T10:23:53Z</dc:date>
    </item>
    <item>
      <title>Re: help need on the event count parameter of signatures</title>
      <link>https://community.cisco.com/t5/network-security/help-need-on-the-event-count-parameter-of-signatures/m-p/647111#M87935</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi  Sebastian ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have answered your question on the Firewalling area ..  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Hi ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The signature will perform the action specified on the signature .. the count event is to control the ammount of alerts you received .. in your case you will receive one alert everytime the signature fires 5 times within 10 seconds.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps .. please rate if it it does !!! "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Dec 2006 20:40:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-need-on-the-event-count-parameter-of-signatures/m-p/647111#M87935</guid>
      <dc:creator>Fernando_Meza</dc:creator>
      <dc:date>2006-12-25T20:40:49Z</dc:date>
    </item>
    <item>
      <title>Re: help need on the event count parameter of signatures</title>
      <link>https://community.cisco.com/t5/network-security/help-need-on-the-event-count-parameter-of-signatures/m-p/647112#M87936</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi buddy thanks for ur reply. but i would like to correct u . the event count value is not for controlling the alerts on the ips. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it;s basically specifies the number of times the event has to occur for the signature to trigger. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i modified the icmp echo request signature. and set the event count to 6 and the signature action to produce alert. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now if i send 5 icmp echo request the signature doesn;t get fired nor the event is written to the event store. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sebastan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Dec 2006 15:53:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-need-on-the-event-count-parameter-of-signatures/m-p/647112#M87936</guid>
      <dc:creator>sebastan_bach</dc:creator>
      <dc:date>2006-12-26T15:53:03Z</dc:date>
    </item>
    <item>
      <title>Re: help need on the event count parameter of signatures</title>
      <link>https://community.cisco.com/t5/network-security/help-need-on-the-event-count-parameter-of-signatures/m-p/647113#M87937</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;mm  ..  good that you mentioned because the decription on the CCSP book is not very clear &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Dec 2006 01:37:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-need-on-the-event-count-parameter-of-signatures/m-p/647113#M87937</guid>
      <dc:creator>Fernando_Meza</dc:creator>
      <dc:date>2006-12-27T01:37:19Z</dc:date>
    </item>
  </channel>
</rss>

