<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Filtering verbose alerts in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/filtering-verbose-alerts/m-p/450913#M95445</link>
    <description>&lt;P&gt;Greetings all. I'm having some difficulties implementing event filters for a 4215 running 5.0.4.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. I've globally enabled verbose alerting via the CLI by doing&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# service event-action-rules rules0&lt;/P&gt;&lt;P&gt;# overrides produce-verbose-alert&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. I want to filter 'TCP SYN Port Sweep' (3002 0) so it doesn't get logged to the idsEventStore. I've created the following single filter,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# service event-action-rules rules0&lt;/P&gt;&lt;P&gt;# filters insert foo begin&lt;/P&gt;&lt;P&gt;# signature-id 3002&lt;/P&gt;&lt;P&gt;# subsignature-id-range 0-10&lt;/P&gt;&lt;P&gt;# actions-to-remove produce-verbose-alert&lt;/P&gt;&lt;P&gt;# filter-item-status Enabled&lt;/P&gt;&lt;P&gt;# stop-on-match True&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I save my changes and when running local scans I see the event still being logged but WITHOUT the triggerPacket info. OK, I edit the rule and change to&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# actions-to-remove produce-alert&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;run scans again and the event appears in the idsEventStore WITH the triggerPacket.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It appears I have to create two identical filter rules, first one with&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# actions-to-remove produce-verbose-alert&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;next one with,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# actions-to-remove produce-alert&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in order to completely filter 'TCP SYN Port Sweep' from the idsEventStore and I don't see it. So my question to the group is,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How does one create a single event filter rule to drop verbose alerts? Note: I need to have produce-verbose-alert set globally for troubleshooting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for the assistance.&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 09:37:07 GMT</pubDate>
    <dc:creator>gdntsoc</dc:creator>
    <dc:date>2019-03-10T09:37:07Z</dc:date>
    <item>
      <title>Filtering verbose alerts</title>
      <link>https://community.cisco.com/t5/network-security/filtering-verbose-alerts/m-p/450913#M95445</link>
      <description>&lt;P&gt;Greetings all. I'm having some difficulties implementing event filters for a 4215 running 5.0.4.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. I've globally enabled verbose alerting via the CLI by doing&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# service event-action-rules rules0&lt;/P&gt;&lt;P&gt;# overrides produce-verbose-alert&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. I want to filter 'TCP SYN Port Sweep' (3002 0) so it doesn't get logged to the idsEventStore. I've created the following single filter,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# service event-action-rules rules0&lt;/P&gt;&lt;P&gt;# filters insert foo begin&lt;/P&gt;&lt;P&gt;# signature-id 3002&lt;/P&gt;&lt;P&gt;# subsignature-id-range 0-10&lt;/P&gt;&lt;P&gt;# actions-to-remove produce-verbose-alert&lt;/P&gt;&lt;P&gt;# filter-item-status Enabled&lt;/P&gt;&lt;P&gt;# stop-on-match True&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I save my changes and when running local scans I see the event still being logged but WITHOUT the triggerPacket info. OK, I edit the rule and change to&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# actions-to-remove produce-alert&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;run scans again and the event appears in the idsEventStore WITH the triggerPacket.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It appears I have to create two identical filter rules, first one with&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# actions-to-remove produce-verbose-alert&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;next one with,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# actions-to-remove produce-alert&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in order to completely filter 'TCP SYN Port Sweep' from the idsEventStore and I don't see it. So my question to the group is,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How does one create a single event filter rule to drop verbose alerts? Note: I need to have produce-verbose-alert set globally for troubleshooting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for the assistance.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:37:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/filtering-verbose-alerts/m-p/450913#M95445</guid>
      <dc:creator>gdntsoc</dc:creator>
      <dc:date>2019-03-10T09:37:07Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering verbose alerts</title>
      <link>https://community.cisco.com/t5/network-security/filtering-verbose-alerts/m-p/450914#M95447</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When creating a filter you can specify multiple actions to remove.  In IDM you hold down the control key to select each additional action.  In IDM I think you put a "|" between each action you want to remove:  "produceAlert|produceVerboseAlert".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will need to use the one filter to remove All actions that produce any kind of alert. &lt;/P&gt;&lt;P&gt;So you need to remove the following actions at a minimum:&lt;/P&gt;&lt;P&gt;produceAlert&lt;/P&gt;&lt;P&gt;produceVerboseAlert&lt;/P&gt;&lt;P&gt;requestSnmpTrap&lt;/P&gt;&lt;P&gt;logAttackerPackets&lt;/P&gt;&lt;P&gt;logVictimPackets&lt;/P&gt;&lt;P&gt;logPairPackets&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The last 5 actions above will force an alert to be produced Even if produceAlert has been filtered out.  So you have to remove them as well.  This is sort of stated in the IDM guide:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids11/idmguide/dmevtrul.htm#wp1062278" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids11/idmguide/dmevtrul.htm#wp1062278&lt;/A&gt;&lt;/P&gt;&lt;P&gt;But was not made clear in the CLI guide.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to prevent all the actions (including those that don't produce an alert) then enter every action in the actions to remove section.&lt;/P&gt;&lt;P&gt;(NOTE: This is much easier to do in IDM.  You select the top action, Hold down Shift key, and select the last action, and all the actions will be selected for removal).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It sounds like you are not interested in the 3002 signature at all.  If this is the case, then the simplest thing to do is to just Disable the signature, and not worry about the filters.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The filters shoudl really only be used if you want to filter for specific address ranges, or want to filter out some but not all of the actions.&lt;/P&gt;&lt;P&gt;If you want to filter out All actions for All ip addresses, then just Disable the signature instead.&lt;/P&gt;&lt;P&gt;It will save on internal processing within the sensor.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Sep 2005 21:28:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/filtering-verbose-alerts/m-p/450914#M95447</guid>
      <dc:creator>marcabal</dc:creator>
      <dc:date>2005-09-01T21:28:20Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering verbose alerts</title>
      <link>https://community.cisco.com/t5/network-security/filtering-verbose-alerts/m-p/450915#M95449</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, I did fail to mention that I DO want to filter out verbose alerting for specific ip ranges. Using the CLI is it possible to specify multiple actions to remove using a single statement, for example,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#actions-to-remove produce-alert produce-verbose-alert&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or will I need to create multiple filters, one for each. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Sep 2005 12:37:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/filtering-verbose-alerts/m-p/450915#M95449</guid>
      <dc:creator>gdntsoc</dc:creator>
      <dc:date>2005-09-02T12:37:51Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering verbose alerts</title>
      <link>https://community.cisco.com/t5/network-security/filtering-verbose-alerts/m-p/450916#M95451</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had a typo in my earlier response.&lt;/P&gt;&lt;P&gt;One of the lines should have read:&lt;/P&gt;&lt;P&gt;In the CLI you put a "|" between each action you want to remove: "produceAlert|produceVerboseAlert".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To remove all actions the CLI configuration line in that filter would look like:&lt;/P&gt;&lt;P&gt;actions-to-remove request-block-connection|request-block-host|deny-attacker-inline|deny-packet-inline|deny-connection-inline|log-attacker-packets|log-victim-packets|log-pair-packets|reset-tcp-connection|produce-alert|produce-verbose-alert|request-snmp-trap &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Sep 2005 15:02:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/filtering-verbose-alerts/m-p/450916#M95451</guid>
      <dc:creator>marcabal</dc:creator>
      <dc:date>2005-09-02T15:02:05Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering verbose alerts</title>
      <link>https://community.cisco.com/t5/network-security/filtering-verbose-alerts/m-p/450917#M95453</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the same problem as  gdntsoc in my IPS 4240.  Basically I want to  created a filter for a &lt;/P&gt;&lt;P&gt;signature to trigger only for a specific destination address. It seems that the event&lt;/P&gt;&lt;P&gt;filter I created for TCP SYN Port Sweep does not work. The secmon event monitoring still&lt;/P&gt;&lt;P&gt;shows that ip outside the my ip space in my filter is still being log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following are the settings of the filter event:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1st filter (Trigger the signature on this address)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  Filter name : filter1&lt;/P&gt;&lt;P&gt;  SigId : 3002&lt;/P&gt;&lt;P&gt;  SubSig: 0-255 (default)&lt;/P&gt;&lt;P&gt;  Attacker Address: 0.0.0.0-255.255.255.0 (default)&lt;/P&gt;&lt;P&gt;  Ports : 0-65535 (default)&lt;/P&gt;&lt;P&gt;  Victim Address : 10.10.10.10 - 10.10.10.90&lt;/P&gt;&lt;P&gt;  Ports : 0-65535 (default)&lt;/P&gt;&lt;P&gt;  RR Thrsh Range : 0-100 (default)&lt;/P&gt;&lt;P&gt;  Action to subtract : none (default)&lt;/P&gt;&lt;P&gt;  Stop on Match : True&lt;/P&gt;&lt;P&gt;  Enabled ; True&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2nd filter (Disable/Filter the signature on other address)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  Filter name : filter2&lt;/P&gt;&lt;P&gt;  SigId : 3002&lt;/P&gt;&lt;P&gt;  SubSig: 0-255 (default)&lt;/P&gt;&lt;P&gt;  Attacker Address: 0.0.0.0-255.255.255.0 (default)&lt;/P&gt;&lt;P&gt;  Ports : 0-65535 (default)&lt;/P&gt;&lt;P&gt;  Victim Address : 0.0.0.0-255.255.255.0 (default)&lt;/P&gt;&lt;P&gt;  Ports : 0-65535 (default)&lt;/P&gt;&lt;P&gt;  RR Thrsh Range : 0-100 (default)&lt;/P&gt;&lt;P&gt;  Action to subtract : none (log-attacker packets|log pair-pockets|log-victim-packets|&lt;/P&gt;&lt;P&gt;			     produce-alerts|produce-verbose-alerts)&lt;/P&gt;&lt;P&gt;  Stop on Match : True&lt;/P&gt;&lt;P&gt;  Enabled ; True&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;  I want this filter to operate so to avoid over &lt;/P&gt;&lt;P&gt;log it produce on the eventstore. Is there a problem &lt;/P&gt;&lt;P&gt;with my settings??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Jander&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Sep 2005 00:42:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/filtering-verbose-alerts/m-p/450917#M95453</guid>
      <dc:creator>janderjulot</dc:creator>
      <dc:date>2005-09-22T00:42:18Z</dc:date>
    </item>
  </channel>
</rss>

