<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: False positive filter in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/false-positive-filter/m-p/446267#M95263</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi I would really appreciate if some one would help me in this ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is about documentation process , If Security team figure out there is a false positive alarm , and want to add a filter or disbale an alarm , what is the noraml practice in the organization , Do they normally raize a change contriol to do it , Or have any security meeting with Server , Network team to develop a consensus what we need to do with this False alarm like disable the alarm or add filter.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 14 Jan 2010 11:13:51 GMT</pubDate>
    <dc:creator>whhtnetwork</dc:creator>
    <dc:date>2010-01-14T11:13:51Z</dc:date>
    <item>
      <title>False positive filter</title>
      <link>https://community.cisco.com/t5/network-security/false-positive-filter/m-p/446265#M95261</link>
      <description>&lt;P&gt;I have IDS 4250 running 5.0 software. I mange it through IPSMC . I am getting lots of false positive on my IPSMC security monitor console. How do i filter it so it does not shows up in security monitor. In IDS 4.X version there was an option in IDSMC to create filter and exclude those false positives . I dont know how to do in in IPSMC with version 5.0. Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:42:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/false-positive-filter/m-p/446265#M95261</guid>
      <dc:creator>altaf007</dc:creator>
      <dc:date>2019-03-10T09:42:41Z</dc:date>
    </item>
    <item>
      <title>Re: False positive filter</title>
      <link>https://community.cisco.com/t5/network-security/false-positive-filter/m-p/446266#M95262</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Use the "SigEvent Action Filters" section to create filters.  These are the basic filters you know in v4.x but a lot more powerful now.  For example, if you have actions on a particular sig of say, Produce Alert and TCP Reset, you can create a SigEvent Action Filter to just not do the TCP Reset if this sig fires for a certain address, etc.  Before you pretty much just filtered the entire alert, but now you can filter particular actions on alerts (hence the name change).  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the only action you have on a particular signature is Produce Alert, then filter that action out in your new SigEvent Action Filter, and that in effect is doing the same thing as the filtering in v4.x.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Oct 2005 04:41:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/false-positive-filter/m-p/446266#M95262</guid>
      <dc:creator>gfullage</dc:creator>
      <dc:date>2005-10-25T04:41:09Z</dc:date>
    </item>
    <item>
      <title>Re: False positive filter</title>
      <link>https://community.cisco.com/t5/network-security/false-positive-filter/m-p/446267#M95263</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi I would really appreciate if some one would help me in this ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is about documentation process , If Security team figure out there is a false positive alarm , and want to add a filter or disbale an alarm , what is the noraml practice in the organization , Do they normally raize a change contriol to do it , Or have any security meeting with Server , Network team to develop a consensus what we need to do with this False alarm like disable the alarm or add filter.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jan 2010 11:13:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/false-positive-filter/m-p/446267#M95263</guid>
      <dc:creator>whhtnetwork</dc:creator>
      <dc:date>2010-01-14T11:13:51Z</dc:date>
    </item>
  </channel>
</rss>

