<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: tuning 3883 by attacker IP in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/tuning-3883-by-attacker-ip/m-p/611577#M92476</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;event action filters are used to subtract actions (not add) based on the filtering criteria.  It's very clear when directly managing the sensor, it may not be so clear in VMS. So, you need to create an event action filter for that attacker ip.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;as far as lowering the severity...the only way to do that is by modifying the specific signature.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 07 Sep 2006 01:23:41 GMT</pubDate>
    <dc:creator>mhellman</dc:creator>
    <dc:date>2006-09-07T01:23:41Z</dc:date>
    <item>
      <title>tuning 3883 by attacker IP</title>
      <link>https://community.cisco.com/t5/network-security/tuning-3883-by-attacker-ip/m-p/611574#M92473</link>
      <description>&lt;P&gt;how can I tune sig 3883 by attacker IP?  Our VMS server is triggering this alert when it hits cisco (probably for sig updates) so i want to tune the sig so it ignores alerts from the VMS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i dont see an option under "tune" for that signature for the attacker or victim IPs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:12:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tuning-3883-by-attacker-ip/m-p/611574#M92473</guid>
      <dc:creator>slug420</dc:creator>
      <dc:date>2019-03-10T10:12:07Z</dc:date>
    </item>
    <item>
      <title>Re: tuning 3883 by attacker IP</title>
      <link>https://community.cisco.com/t5/network-security/tuning-3883-by-attacker-ip/m-p/611575#M92474</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You don't need tune the signature, you need to create an event action filter.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Sep 2006 17:05:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tuning-3883-by-attacker-ip/m-p/611575#M92474</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2006-09-06T17:05:16Z</dc:date>
    </item>
    <item>
      <title>Re: tuning 3883 by attacker IP</title>
      <link>https://community.cisco.com/t5/network-security/tuning-3883-by-attacker-ip/m-p/611576#M92475</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i was looking in that area but did not see a way that the event action filter could generate no event, or an event of a lower severity level than was set on the signature itself.  All that looked to let me do was tell it was action to take, IE shun, block, reset, alarm, etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i want it to do nothing if it is an attacker ip of x.x.x.x or s.s.s.s&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Sep 2006 23:09:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tuning-3883-by-attacker-ip/m-p/611576#M92475</guid>
      <dc:creator>slug420</dc:creator>
      <dc:date>2006-09-06T23:09:50Z</dc:date>
    </item>
    <item>
      <title>Re: tuning 3883 by attacker IP</title>
      <link>https://community.cisco.com/t5/network-security/tuning-3883-by-attacker-ip/m-p/611577#M92476</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;event action filters are used to subtract actions (not add) based on the filtering criteria.  It's very clear when directly managing the sensor, it may not be so clear in VMS. So, you need to create an event action filter for that attacker ip.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;as far as lowering the severity...the only way to do that is by modifying the specific signature.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Sep 2006 01:23:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tuning-3883-by-attacker-ip/m-p/611577#M92476</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2006-09-07T01:23:41Z</dc:date>
    </item>
  </channel>
</rss>

