03-11-2005 05:51 AM - edited 03-10-2019 01:19 AM
Has anybody ran into the trouble of the Cisco Works Security monitor for IDSs not getting an alarm. We have a virus in our network, sig 3030 tcp host sweep, and the IDS version Sig149, Sees the signature but it is not sending it to the Cisco Works Server. I see the alarm on the IDS box but not Cisco Works. I see other alarms on Cicso works though. Just not all of them. I checked to make sure that signature was turned on on the MC and it is. Anybody have any ideas what is wrong with my IDS box or my MC? Any help would be great. Thanks Justin
03-11-2005 10:49 AM
The first thing that comes to mind is checking to see that the CiscoWorks server is in trusted hosts on the sensor. If so, verify the credentials are correct in SecMon.
03-11-2005 11:08 AM
Done and Done. Everything looks good. I am recieving alarms, just not all of them. It is like the IDS sees it as a problem and the SC does not.
03-11-2005 12:30 PM
Well, sig 3030 is by default an informational alert. What's the minimum logging level for the sensor in SecMon?
03-11-2005 01:15 PM
I dont even see an option for that. Where would that be found?
03-11-2005 01:46 PM
Go to the devices tab in SecMon and edit the sensor entry. There you should see the setting.
03-11-2005 01:34 PM
mcvosi, you totally rock. That fixed the problem. I found it. I have been beating my head on the table for weeks trying to figure this out. I saw that before but it was greyed out so I figured it was not active. What I learned is you have to edit the device inoreder to change that. Again, thanks a ton.
Justin
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide