2071
Views
0
Helpful
1
Replies
FireSIGHT System generates connection events although logging is disabled
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-08-2014 06:15 AM - edited 03-12-2019 05:34 AM
Although all Connection Logging options are disabled in an Access Control policy, my Sourcefire FireSIGHT System still generates a Connection Event.
Labels:
- Labels:
-
NGIPS
1 Reply 1
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-08-2014 06:19 AM
Reason
A Sourcefire FireSIGHT System generates a Connection Event when an Intrusion Event is generated. A Connection Event is generated on the web interface of the Sourcefire FireSIGHT Management Center for the following reasons:
- Intrusion Block
- Intrusion Monitor
Solution
If this feature is undesired, it may be disabled from the shell using the following command:
> configure log-ips-connection disable
