11-28-2013 09:02 PM - edited 03-10-2019 06:06 AM
Hi Cisco IPS Expert,
I am seeing event in our IPS that shows victim IP is 0.0.0.0.
Some informed that this is a summarized event.
But how can I get details of victim IP if i need to know .
Regards,
Jhun
Solved! Go to Solution.
12-02-2013 09:09 AM
You can edit the signature to change the summarization and force it to fire for each victim IP address.
This will result in MANY more signatures firing on your device. Please take this into account if your IPS sensor is already heavily loaded.
http://www.cisco.com/en/US/tech/tk1068/technologies_configuration_example09186a0080c03908.shtml
- Bob
12-03-2013 08:47 AM
Juhn -
Yes, anytime you see the 0.0.0.0 address used in the victim IP address field it is the result of multiple victim IP addresses being summarized. I have seen signatures that will tell you the first 10 or so IP addresses that were summarized by looking at the detailed event. I'm not sure if all summarized signatures details show this, but that would be the only way I could imagine to see the IP addresses of past events.
- Bob
12-02-2013 09:09 AM
You can edit the signature to change the summarization and force it to fire for each victim IP address.
This will result in MANY more signatures firing on your device. Please take this into account if your IPS sensor is already heavily loaded.
http://www.cisco.com/en/US/tech/tk1068/technologies_configuration_example09186a0080c03908.shtml
- Bob
12-02-2013 05:49 PM
Hi Bob,
Thank you for your reponse. I did as instructed. Just waiting for the next even to occur.
So this means I can no longer see the IP details of the victim IP on the previous events.?
Please confirm as well that 0.0.0.0 IP is due to summarization and not as "any host".
-Jhun
12-03-2013 08:47 AM
Juhn -
Yes, anytime you see the 0.0.0.0 address used in the victim IP address field it is the result of multiple victim IP addresses being summarized. I have seen signatures that will tell you the first 10 or so IP addresses that were summarized by looking at the detailed event. I'm not sure if all summarized signatures details show this, but that would be the only way I could imagine to see the IP addresses of past events.
- Bob
12-03-2013 07:50 PM
Thankf for your help.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide