cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
774
Views
0
Helpful
2
Replies

IPS Event Action Filters - Adding variables to the Attacker/Victim Fields

rmeans
Level 3
Level 3

Regarding Event Action Filters. How do you add multiple event variables to the attacker and victim fields? I use a comma to separate IP addresses (10.10.1.1,192.168.1.1). When I use a variable ($inside) I have not been able to add any other IP addresses or variables ($dmz) in the same filter rule. Is it possible to have two variables in the same attacker/victim fields? I would have thought $inside,$dmz might work but I get an error. I have also tried $inside\,$dmz and $inside ,$dmz and $inside \,$dmz but get errors saying system variable not found.

1 Accepted Solution

Accepted Solutions

marcabal
Cisco Employee
Cisco Employee

Only one variable is currently allowed in a field.

There is an enhancement request to support multiple variables in a field, but this has not been targeted for any specific release yet.

View solution in original post

2 Replies 2

marcabal
Cisco Employee
Cisco Employee

Only one variable is currently allowed in a field.

There is an enhancement request to support multiple variables in a field, but this has not been targeted for any specific release yet.

I was surprised to see this discussion from 2007 when it still appears to be the case in 2013 of only one event variable per field. Is there a specific decade targeted for this enhancement?

Thanks,
Mark

Review Cisco Networking for a $25 gift card