cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1655
Views
0
Helpful
6
Replies

IronPort ESA Outbreak filters or rule bad?

BrianRoberson
Level 1
Level 1

ESA went nuts in the last thirty minutes and started quarantining email into outbreak quarantine.  I'm guessing Cisco released a bad definition/rule?

 

Waiting on guidance from Cisco...

6 Replies 6

nicktang
Level 1
Level 1

mail being quarantined and deleted for reason "Scam: Fake Deal"

Exactly what I am seeing.

nickylee
Level 1
Level 1

we are seeing a similar issue - since about 6-7PM Pacific time

 

gmail addresses are being filtered, hotmail, cisco emails are not filtered

 

We are seeing messages even from local servers (eg: internally generated messages which do get filtered by our ESA's) being quarantined with the SUSPICIOUS MESSAGE added to the subject line. It is driving our users crazy, and also creating delays as messages go into the outbreak quarantine.

 

It seems like it may be resolved now. Hopeflly!

 

     
     
     
     

Seems to be resolved now as well.

 

Hey Everyone,

I sincerely apologise for the issues noted.
You are correct at approximately 9:56PM EST on the 2nd of April - there was a new outbreak filter rule pushed out that was misfiring and causing the false positive matches.

TAC had engaged the Talos team for escalation to correct this and the fix was put forward on the early hours of 3rd of April.

Regards,
Matthew