<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic fire once summary mode question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fire-once-summary-mode-question/m-p/530253#M98390</link>
    <description>&lt;P&gt;let's say I have signature with the following characteristics:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Event Counter&lt;/P&gt;&lt;P&gt;-------------&lt;/P&gt;&lt;P&gt;Event Count: 1&lt;/P&gt;&lt;P&gt;Event Count Key: Attacker and Victim addresses&lt;/P&gt;&lt;P&gt;Specifiy Alert Interval: No&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alert Frequency&lt;/P&gt;&lt;P&gt;---------------&lt;/P&gt;&lt;P&gt;Summary Mode: Fire Once&lt;/P&gt;&lt;P&gt;Summary Key: attacker and victim addresses&lt;/P&gt;&lt;P&gt;Specify Global Summary Threshold: No&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Obviously, it will alarm for the first event, but what about subsequent events? Testing reveals that it does eventually generate more alarms...but how much time much pass?&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 10:05:15 GMT</pubDate>
    <dc:creator>mhellman</dc:creator>
    <dc:date>2019-03-10T10:05:15Z</dc:date>
    <item>
      <title>fire once summary mode question</title>
      <link>https://community.cisco.com/t5/network-security/fire-once-summary-mode-question/m-p/530253#M98390</link>
      <description>&lt;P&gt;let's say I have signature with the following characteristics:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Event Counter&lt;/P&gt;&lt;P&gt;-------------&lt;/P&gt;&lt;P&gt;Event Count: 1&lt;/P&gt;&lt;P&gt;Event Count Key: Attacker and Victim addresses&lt;/P&gt;&lt;P&gt;Specifiy Alert Interval: No&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alert Frequency&lt;/P&gt;&lt;P&gt;---------------&lt;/P&gt;&lt;P&gt;Summary Mode: Fire Once&lt;/P&gt;&lt;P&gt;Summary Key: attacker and victim addresses&lt;/P&gt;&lt;P&gt;Specify Global Summary Threshold: No&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Obviously, it will alarm for the first event, but what about subsequent events? Testing reveals that it does eventually generate more alarms...but how much time much pass?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:05:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fire-once-summary-mode-question/m-p/530253#M98390</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2019-03-10T10:05:15Z</dc:date>
    </item>
    <item>
      <title>Re: fire once summary mode question</title>
      <link>https://community.cisco.com/t5/network-security/fire-once-summary-mode-question/m-p/530254#M98391</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The amount of time is indicated by the Summary Interval (Time in seconds used in each summary alert).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think by default, signatures are set to 15 seconds.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 09 Jul 2006 07:35:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fire-once-summary-mode-question/m-p/530254#M98391</guid>
      <dc:creator>craig.lepchenske</dc:creator>
      <dc:date>2006-07-09T07:35:25Z</dc:date>
    </item>
    <item>
      <title>Re: fire once summary mode question</title>
      <link>https://community.cisco.com/t5/network-security/fire-once-summary-mode-question/m-p/530255#M98392</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;AFAICT, there is no summary interval for the "fire once" summary mode.  It is not exposed to the user for viewing/modification anyway.  15 seconds doesn't seem likely given the testing I did.  It was ~2 minutes that a new alarm would fire.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Jul 2006 14:53:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fire-once-summary-mode-question/m-p/530255#M98392</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2006-07-10T14:53:13Z</dc:date>
    </item>
  </channel>
</rss>

