cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
391
Views
0
Helpful
1
Replies

ids event viewer alarm

a.carnevali
Level 1
Level 1

I've many alarms with more than one signature with destination ip address 0.0.0.0 source and destination port 0

how can I intend these messages?

1 Reply 1

owillins
Level 6
Level 6

Begin by defining an exclusive filter. Specify the source address, which is the network that is generating large numbers of false positives. Specify all signatures so that no alarms are sent to Security Monitor. Next, define an inclusive filter. Specify the same source address but specify Signatures which are the ones that you want to include.

Review Cisco Networking for a $25 gift card