cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
496
Views
0
Helpful
3
Replies

6500 IDSM-2 SigID 994/995

stevew
Level 1
Level 1

I'm getting constant 994/995 flow Starts/Stops. Approximatley every 30seconds. Can't find docs on how to correct this or where to look.

3 Replies 3

mkodali
Cisco Employee
Cisco Employee

This is not an error condition on the part of Sensor to be corrected. These sigs are generated everytime the sniffing interface nic detects a packet after an interval of no activity or when it does not detect any packet till some time. If you don't want to see those alerts, you can disable those sigs, which I hope you know how to.

They have their utility though. If you're using a 3rd party SIMS with a RDEP client, these messages can be used to keep tabs on the sensor.

Consider them a 'hearbeat', especially if your sensor is highly tuned and alerts are rare.

That being said, they are otherwise generally expendable...

Alex Arndt

Thanks. From the cisco docs it made it sound like a sensor error. I've already disabled them.

Review Cisco Networking for a $25 gift card