cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
273
Views
0
Helpful
1
Replies

How to show signature definition delta

kst.amand
Level 1
Level 1

Is there a way to show just the modifications / tuning changes made to a default downloaded signature set?

Background - I've downloaded a signature set, tuned a specific signature-id to a deny event-action, and from what I understand changes are recorded in a sigdef-delta.xml file.

What I'm hoping to be able to do is issue a command that allows us just to identify the detlas in order to avoid a bunch of documentation.

Any help?

1 Reply 1

attmidsteam
Level 1
Level 1

If you type 'sh conf' on the CLI on a modern 5.x sensor you will only get the configuration differences (such as different event-actions or different summary keys). The only alternative is to parse out the XML (found on the underlying OS) which is a pain to do (since the XML format isn't completely consistent).

Review Cisco Networking for a $25 gift card