09-19-2006 04:40 AM - edited 03-10-2019 03:13 AM
I created a drop rule, dest and src ip's are "ANY", and the hostnames as seen in MARS. I chose to "drop" as action...not "log to db only". The event is "Inactive CS-MARS reporting device, device is "ANY", severity is "ANY", time range is "ANY" I clicked apply, submit and activate.
How come on my Summary | dashboard screen I still see these incidences. I was hoping this would stop. Is this expected behavior, or have I done something incorrectly?
Thanks,
Bob
09-19-2006 09:53 AM
I vaguely recall reading something about not being able to use a drop rule to prevent these. You have to inactivate the rule.
09-20-2006 06:34 AM
Here is the bug id. It appears to have been fixed now based on your results.
09-19-2006 10:34 PM
I've solved that problem including "ANY" and "0.0.0.0" in the source address. CS-MARS doesn't understand that ANY must include 0.0.0.0.
Concerning to the dashboard you'll see the events for a time, and previous incidents will be saved in the incident list. Since you add "0.0.0.0" in source address, you won't see any inactive cs-mars event. The most important issue filtering that event is that it is a very high amount of events and all reports must be created using "!=Inactive CS-MARS reporting device".
As I told you, from now you won't see that event any more.
Good luck!!
ps: Please, rate the post.
09-20-2006 05:00 AM
Thanks Juceta,
That seems to have solved the problem, no new incidences for the last couple of hours.
Thanks,
Bob
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide