08-28-2007 10:21 AM - edited 03-10-2019 03:46 AM
IPS 6 is reporting the STORM WORM...MARS says it is an Unkown Device Event Type. I have latest code and sigs on all platforms.
Does this report from MARS indicate that I have to train and/or make a catagory or something like that on MARS?
I want MARS to generate a IPS/sig event description just like all of the other sigs on the IPS that are reported to MARS
08-28-2007 10:29 AM
Signature 5894 Storm Worm was released in S298.
The latest Mars release, 4.2.8, only supports up to S294.
08-28-2007 10:36 AM
ok, let say my uppermanagement wants a report that shows the impact of this 'Unknown" on their network. How can I achieve that?
gp
08-28-2007 11:05 AM
Welcome to MARS;-)
MARS is only updated about once every 2-3 months, and this includes signature updates. The latest release (about 2 days ago) understands Cisco IPS signatures up to S294, so it doesn't understand that signature. Why don't you ask management if they can wait until October? LOL.
Anyway, about the best you can do currently is to copy the data into another tool, like Excel, and clean it up.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide