cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
381
Views
0
Helpful
1
Replies

event summarization

mhellman
Level 7
Level 7

I've noticed summary alerts without a preceding non-summarized alert, which I thought was impossible.

Are signatures using a summary mode of "summarize" always supposed to generate 2 alerts, the initial alert that starts the counter and then a summarized alert?

The only explanation I can think of is the event filters. Is it possible that an event filter [especially one with "stop on match" disabled] would prevent the initial alert but not the summarized alert?

1 Reply 1

ebreniz
Level 6
Level 6

That looks strange to me too. Summary alarms gets triggered at the end of the throttle-interval. If summarization is configured for a signature, then the first alarm is sent when it occurs and all other alarms are blocked and only a summary alram is sent at the end of the throttle interval.

http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids10/idmiev/swappa.htm#wp787013

Review Cisco Networking for a $25 gift card