<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Security monitor NSDB link looks up wrong sigsubid in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/security-monitor-nsdb-link-looks-up-wrong-sigsubid/m-p/584332#M90328</link>
    <description>&lt;P&gt;I found that when I use security monitor to lookup the explanation of a signature event that it always looks up the signature with subid of 0 even if the actual subid is something else.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://tools.cisco.com/MySDN/Intelligence/viewSignature.x?signatureId=3327&amp;amp;signatureSubId=0" target="_blank"&gt;http://tools.cisco.com/MySDN/Intelligence/viewSignature.x?signatureId=3327&amp;amp;signatureSubId=0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The actual subid of this event as seen using IDM is subid=6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is very misleading because in the example above subid=0 has no known benign triggers, but subid=6 does have reported false positives.  Until I happened to use the IDM event viewer and saw the actual subid, I could only conclude that this was likely malicious activity.  This wouldn't be as bad if the detail pain of security monitor listed the subid, but it doesn't. It only has the base id of the signature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone else seen this and know of a way to correct it?  I don't want to have to use IDM to verify the subid for every alert.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 09:55:20 GMT</pubDate>
    <dc:creator>MARK BAKER</dc:creator>
    <dc:date>2019-03-10T09:55:20Z</dc:date>
    <item>
      <title>Security monitor NSDB link looks up wrong sigsubid</title>
      <link>https://community.cisco.com/t5/network-security/security-monitor-nsdb-link-looks-up-wrong-sigsubid/m-p/584332#M90328</link>
      <description>&lt;P&gt;I found that when I use security monitor to lookup the explanation of a signature event that it always looks up the signature with subid of 0 even if the actual subid is something else.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://tools.cisco.com/MySDN/Intelligence/viewSignature.x?signatureId=3327&amp;amp;signatureSubId=0" target="_blank"&gt;http://tools.cisco.com/MySDN/Intelligence/viewSignature.x?signatureId=3327&amp;amp;signatureSubId=0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The actual subid of this event as seen using IDM is subid=6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is very misleading because in the example above subid=0 has no known benign triggers, but subid=6 does have reported false positives.  Until I happened to use the IDM event viewer and saw the actual subid, I could only conclude that this was likely malicious activity.  This wouldn't be as bad if the detail pain of security monitor listed the subid, but it doesn't. It only has the base id of the signature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone else seen this and know of a way to correct it?  I don't want to have to use IDM to verify the subid for every alert.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:55:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-monitor-nsdb-link-looks-up-wrong-sigsubid/m-p/584332#M90328</guid>
      <dc:creator>MARK BAKER</dc:creator>
      <dc:date>2019-03-10T09:55:20Z</dc:date>
    </item>
    <item>
      <title>Re: Security monitor NSDB link looks up wrong sigsubid</title>
      <link>https://community.cisco.com/t5/network-security/security-monitor-nsdb-link-looks-up-wrong-sigsubid/m-p/584333#M90329</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The user will see duplicate names for sub-signatures with the same General Signature parent.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This defect will occur for the few sub-signatures whose parent General signatures have two or more sub-signatures.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It occurs because the sub-signature inherits its name from its General signature parent.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is currently no workaround to display unique sub-signature names and the NSDB does not provide information that allows the user to identify the sub-signature by sub-sig ID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Mar 2006 15:31:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-monitor-nsdb-link-looks-up-wrong-sigsubid/m-p/584333#M90329</guid>
      <dc:creator>a-vazquez</dc:creator>
      <dc:date>2006-03-14T15:31:34Z</dc:date>
    </item>
    <item>
      <title>Re: Security monitor NSDB link looks up wrong sigsubid</title>
      <link>https://community.cisco.com/t5/network-security/security-monitor-nsdb-link-looks-up-wrong-sigsubid/m-p/584334#M90331</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;take note of:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=Intrusion%20Prevention%20Systems/IDS&amp;amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.1ddae323" target="_blank"&gt;http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=Intrusion%20Prevention%20Systems/IDS&amp;amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.1ddae323&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it helps, rate the post&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Apr 2006 08:18:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-monitor-nsdb-link-looks-up-wrong-sigsubid/m-p/584334#M90331</guid>
      <dc:creator>darin.marais</dc:creator>
      <dc:date>2006-04-26T08:18:42Z</dc:date>
    </item>
    <item>
      <title>Re: Security monitor NSDB link looks up wrong sigsubid</title>
      <link>https://community.cisco.com/t5/network-security/security-monitor-nsdb-link-looks-up-wrong-sigsubid/m-p/584335#M90332</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you.  That did answer my question.  Unfortunately the bug has not been resolved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Apr 2006 11:46:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-monitor-nsdb-link-looks-up-wrong-sigsubid/m-p/584335#M90332</guid>
      <dc:creator>MARK BAKER</dc:creator>
      <dc:date>2006-04-26T11:46:16Z</dc:date>
    </item>
    <item>
      <title>Re: Security monitor NSDB link looks up wrong sigsubid</title>
      <link>https://community.cisco.com/t5/network-security/security-monitor-nsdb-link-looks-up-wrong-sigsubid/m-p/584336#M90333</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mark, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a temporary patch out but you will need to contact Cisco TAC. It will probably be included in the next SecMon update.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Apr 2006 07:46:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-monitor-nsdb-link-looks-up-wrong-sigsubid/m-p/584336#M90333</guid>
      <dc:creator>darin.marais</dc:creator>
      <dc:date>2006-04-27T07:46:27Z</dc:date>
    </item>
  </channel>
</rss>

