cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
744
Views
0
Helpful
2
Replies
Beginner

IPS signature layer reports ?

Hello!

I'm using Sourcefire IPS and I'm reviewing the signature alerts... I scheduled a report that show me which specific snort signature triggered in a specific time frame, something like:

 

SIGNATURE NAME , NUMBER OF EVENTS, SEVERITY  

 

Because we use different layers in the intrusion policy will be very useful to add to the report the layer in which the signature are.
(The reason of this is that a specific layer is including the latest snort rules, while the others older ones, so I would like to filter the events based on the layer to investigate only the new ones and not previous events.)

 

The output should be a report in csv like:

SIGNATURE NAME , NUMBER OF EVENTS, SEVERITY  , ( Layer )

 

Do you know how to export this? What is the best way to review these events? Any experience?

 

Many thanks! Ric

2 REPLIES 2
Rising star

Re: IPS signature layer reports ?

From my experience source fire is excellent IPS/IDS however, when it come to reporting its not as good.

please do not forget to rate.
Highlighted
Beginner

Re: IPS signature layer reports ?

Hello,

any advice on the topic?