cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

3093
Views
5
Helpful
3
Replies
Highlighted

Cisco Sourcefire Intrusion and File event Rate Alert

Hi Team,

 

We are receiving critical Alert in the FMC related to INTRUSION AND FILE EVENT RATE ALERT. And the in the Description Events per second is 58.524. Is it because of more Intrusion and File Attacks Detected. How to check this details. ? Kindly request your assistance on this.

 

Thanks,

-Vishnu

1 ACCEPTED SOLUTION

Accepted Solutions
Highlighted
Cisco Employee

Hello Vishu,

for example you can investigate Summary Dashboard after "Intrusion and file event rate" alert is seen on FMC appliance. You will be able to see number of total amount of IPS events, potential spikes with IPS event rates, Top targets and when you click on the graph data you will be redirected to the IPS events that trigger that time to get more details along with specific timestamp.

Critical alert will be seen anytime appliance see over 50 IPS/file events per second, if those events are expected in your network environment you can adjust this value in health policy to higher number.

Best regards,

Veronika

View solution in original post

3 REPLIES 3
Highlighted
Cisco Employee

Hello Vishu,

for example you can investigate Summary Dashboard after "Intrusion and file event rate" alert is seen on FMC appliance. You will be able to see number of total amount of IPS events, potential spikes with IPS event rates, Top targets and when you click on the graph data you will be redirected to the IPS events that trigger that time to get more details along with specific timestamp.

Critical alert will be seen anytime appliance see over 50 IPS/file events per second, if those events are expected in your network environment you can adjust this value in health policy to higher number.

Best regards,

Veronika

View solution in original post

Highlighted

Hi

Is any Impact on device or services by this ?

On my environment its goes to 150-200.

 

 

Highlighted

Thanks Veronica..

-Vishnu

Content for Community-Ad