- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-28-2013 09:02 PM - edited 03-10-2019 06:06 AM
Hi Cisco IPS Expert,
I am seeing event in our IPS that shows victim IP is 0.0.0.0.
Some informed that this is a summarized event.
But how can I get details of victim IP if i need to know .
Regards,
Jhun
Solved! Go to Solution.
- Labels:
-
IPS and IDS
Accepted Solutions

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-02-2013 09:09 AM
You can edit the signature to change the summarization and force it to fire for each victim IP address.
This will result in MANY more signatures firing on your device. Please take this into account if your IPS sensor is already heavily loaded.
http://www.cisco.com/en/US/tech/tk1068/technologies_configuration_example09186a0080c03908.shtml
- Bob

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-03-2013 08:47 AM
Juhn -
Yes, anytime you see the 0.0.0.0 address used in the victim IP address field it is the result of multiple victim IP addresses being summarized. I have seen signatures that will tell you the first 10 or so IP addresses that were summarized by looking at the detailed event. I'm not sure if all summarized signatures details show this, but that would be the only way I could imagine to see the IP addresses of past events.
- Bob

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-02-2013 09:09 AM
You can edit the signature to change the summarization and force it to fire for each victim IP address.
This will result in MANY more signatures firing on your device. Please take this into account if your IPS sensor is already heavily loaded.
http://www.cisco.com/en/US/tech/tk1068/technologies_configuration_example09186a0080c03908.shtml
- Bob
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-02-2013 05:49 PM
Hi Bob,
Thank you for your reponse. I did as instructed. Just waiting for the next even to occur.
So this means I can no longer see the IP details of the victim IP on the previous events.?
Please confirm as well that 0.0.0.0 IP is due to summarization and not as "any host".
-Jhun

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-03-2013 08:47 AM
Juhn -
Yes, anytime you see the 0.0.0.0 address used in the victim IP address field it is the result of multiple victim IP addresses being summarized. I have seen signatures that will tell you the first 10 or so IP addresses that were summarized by looking at the detailed event. I'm not sure if all summarized signatures details show this, but that would be the only way I could imagine to see the IP addresses of past events.
- Bob
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-03-2013 07:50 PM
Thankf for your help.
