<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Emailing events automatically in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/emailing-events-automatically/m-p/381145#M97706</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Many thanks for the BUG ID. U save my time on open up a TAC case &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;BTW, seem this BUG is already identified for sometime, just wonder when DE will solved it. As the CWVMS is free of charge for 5 hosts now, more and more customer will encounter the problem.&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 23 Nov 2004 01:41:25 GMT</pubDate>
    <dc:creator>jmmleung</dc:creator>
    <dc:date>2004-11-23T01:41:25Z</dc:date>
    <item>
      <title>Emailing events automatically</title>
      <link>https://community.cisco.com/t5/network-security/emailing-events-automatically/m-p/381141#M97696</link>
      <description>&lt;P&gt;On VMS 2.2 with SecMon 1.2.3, the section admin/event rule allows you to send an email. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a requirement to send an email for various signatures when they are triggered on a particular sensor. The email should include the source and the destination address as well as the time, date and count etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I created a rule as follows&lt;/P&gt;&lt;P&gt;Rule Name: Rule&lt;/P&gt;&lt;P&gt;-----------------------------------------------&lt;/P&gt;&lt;P&gt;Comment: &amp;#147;signature description&amp;#148;&lt;/P&gt;&lt;P&gt;-----------------------------------------------&lt;/P&gt;&lt;P&gt;Active: yes&lt;/P&gt;&lt;P&gt;-----------------------------------------------&lt;/P&gt;&lt;P&gt;Filter: (Signature Name = &amp;#147;signature description&amp;#148;) AND&lt;/P&gt;&lt;P&gt;(Originating Device = abc) OR&lt;/P&gt;&lt;P&gt;(Originating Device = xyz) &lt;/P&gt;&lt;P&gt;-----------------------------------------------&lt;/P&gt;&lt;P&gt;Rule Actions:&lt;/P&gt;&lt;P&gt;  Notify via Email:&lt;/P&gt;&lt;P&gt;    Recipient(s): ----&lt;/P&gt;&lt;P&gt;    Subject: Rule&lt;/P&gt;&lt;P&gt;    Message: (Signature Name = &amp;#147;signature description&amp;#148;) AND&lt;/P&gt;&lt;P&gt;(Originating Device = abc) OR (Originating Device = xyz) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following rule: ${RuleName}, has triggered ${MsgCount} times on the ${DateStr} ${TimeStr}&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-----------------------------------------------&lt;/P&gt;&lt;P&gt;Thresholds and Intervals:&lt;/P&gt;&lt;P&gt;  Issue action(s) after 3 event occurrences.&lt;/P&gt;&lt;P&gt;  Repeat action(s) again after 5 event occurrences.&lt;/P&gt;&lt;P&gt;  Reset count every 30 minutes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately it does not seam to work as I thought it would. Could anyone tell me if this is at all possible or even achievable with VMS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The strange thing is that with this rule active, I receive emails even when the &amp;#147;signature description&amp;#148; has not even triggered.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:10:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/emailing-events-automatically/m-p/381141#M97696</guid>
      <dc:creator>darin.marais</dc:creator>
      <dc:date>2019-03-10T09:10:07Z</dc:date>
    </item>
    <item>
      <title>Re: Emailing events automatically</title>
      <link>https://community.cisco.com/t5/network-security/emailing-events-automatically/m-p/381142#M97697</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The following link might help&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2113/products_configuration_example09186a00801fc770.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2113/products_configuration_example09186a00801fc770.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Oct 2004 20:41:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/emailing-events-automatically/m-p/381142#M97697</guid>
      <dc:creator>didyap</dc:creator>
      <dc:date>2004-10-26T20:41:47Z</dc:date>
    </item>
    <item>
      <title>Re: Emailing events automatically</title>
      <link>https://community.cisco.com/t5/network-security/emailing-events-automatically/m-p/381143#M97699</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The script in the suggested CCO tech doc. does not work when the filter rule contain IP address trigger condition. The trigger filter works fine, but the notification email contains empty content!&lt;/P&gt;&lt;P&gt;Any body has workarround, beside MOD the script?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Nov 2004 01:58:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/emailing-events-automatically/m-p/381143#M97699</guid>
      <dc:creator>jmmleung</dc:creator>
      <dc:date>2004-11-19T01:58:15Z</dc:date>
    </item>
    <item>
      <title>Re: Emailing events automatically</title>
      <link>https://community.cisco.com/t5/network-security/emailing-events-automatically/m-p/381144#M97702</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is due to bug CSCed91589 (&lt;A class="jive-link-custom" href="http://www.cisco.com/cgi-bin/Support/Bugtool/onebug.pl?bugid=CSCed91589&amp;amp;Submit=Search" target="_blank"&gt;http://www.cisco.com/cgi-bin/Support/Bugtool/onebug.pl?bugid=CSCed91589&amp;amp;Submit=Search&lt;/A&gt;), unfortunately no workaround at the moment, it's to do with incompatible database entries and needs a major rework.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Severity=High" will work fine, but "Severity=High AND SourceIPAddress=1.1.1.1" will not.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Nov 2004 00:11:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/emailing-events-automatically/m-p/381144#M97702</guid>
      <dc:creator>gfullage</dc:creator>
      <dc:date>2004-11-23T00:11:24Z</dc:date>
    </item>
    <item>
      <title>Re: Emailing events automatically</title>
      <link>https://community.cisco.com/t5/network-security/emailing-events-automatically/m-p/381145#M97706</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Many thanks for the BUG ID. U save my time on open up a TAC case &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;BTW, seem this BUG is already identified for sometime, just wonder when DE will solved it. As the CWVMS is free of charge for 5 hosts now, more and more customer will encounter the problem.&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Nov 2004 01:41:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/emailing-events-automatically/m-p/381145#M97706</guid>
      <dc:creator>jmmleung</dc:creator>
      <dc:date>2004-11-23T01:41:25Z</dc:date>
    </item>
    <item>
      <title>Re: Emailing events automatically</title>
      <link>https://community.cisco.com/t5/network-security/emailing-events-automatically/m-p/381146#M97709</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I currently make use of the script that is listed in this thread I would like to upgrade a system to version 2.01 of secmon/idsmc but  after reading through the release note I noticed the following bug identification which appears to be applicable to the script.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Bug CSCsa12013 &amp;#147;Event Rules ${Query} keyword is incompatible with IdsAlarms in scripts&amp;#148;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are currently no known workarounds for the problem. Could anyone from Cisco advise if there are any plans to fix it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Feb 2005 14:40:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/emailing-events-automatically/m-p/381146#M97709</guid>
      <dc:creator>darin.marais</dc:creator>
      <dc:date>2005-02-03T14:40:18Z</dc:date>
    </item>
    <item>
      <title>Re: Emailing events automatically</title>
      <link>https://community.cisco.com/t5/network-security/emailing-events-automatically/m-p/381147#M97713</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This bug is the same as the aforementioned one in this thread.  It was opened for v2.0 specifically so that it could be tracked and fixed in this release.  It doesn't however, mean that the emailalert.pl script doesn't work in v2.0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have it working currently on 1.2.x, then upgrading to v2.x will have no effect on the functionality of the script.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above bug, and the similar bug opened on v1.2, deal with having more than one Event Filter defined.  In other words, if you have just Severity=High then it'll work fine with v1.2 and v2.x.  If you have Severity=High AND SourceAddress=1.1.1.1 then it won't work in either version.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I said, if it's currently working for you in v1.2, then go ahead and upgrade and it'll keep working for you in v2.0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Feb 2005 00:05:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/emailing-events-automatically/m-p/381147#M97713</guid>
      <dc:creator>gfullage</dc:creator>
      <dc:date>2005-02-04T00:05:39Z</dc:date>
    </item>
  </channel>
</rss>

