06-11-2008 09:31 AM - edited 03-10-2019 04:08 AM
I have a range of IP's that I never want to see any high priority alerts, but need to see any other alerts. How would I do that?
thanks
Solved! Go to Solution.
06-11-2008 05:52 PM
06-11-2008 01:16 PM
The best way to control this would be to filter those hosts based on the Risk Rating, using 'Event Action Filters' you can subtract actions from alerts. So for these hosts you could subtract the 'Product Alert' action based on a specific Risk Rating value.
Have a look at:
http://www.cisco.com/en/US/docs/security/ips/6.0/configuration/guide/idm/dmEvtRul.html#wp1034361
Regards
Farrukh
06-11-2008 03:41 PM
thanks, more detailed information on the risk ratings?
06-11-2008 05:52 PM
Sure, here you go:
Regards
Farrukh
06-12-2008 03:34 PM
Thanks Farrukh
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide