10-16-2007 06:36 AM - edited 03-10-2019 03:49 AM
When I first began to tune the sensor, I went in with the IDM and turned on most of the older trojan definitions just to see if anything was hiding in the network. I have not had any hits on those sigs for a couple of weeks and I would like to set all the trojan sigs back to default (ie back to retired) in one stroke via the CLI. I am running version 5 of the IDS software. Is there an easy way to do this? Thanks.
Solved! Go to Solution.
10-22-2007 10:21 AM
There is no single command that can reset all trojan signatures to their default values. Your best option is to re-apply the lastest service pack (not latest signature udpate) to the Sensor. This will reset most of the signatures to their default values.
10-22-2007 10:21 AM
There is no single command that can reset all trojan signatures to their default values. Your best option is to re-apply the lastest service pack (not latest signature udpate) to the Sensor. This will reset most of the signatures to their default values.
10-22-2007 10:30 AM
Ok, thanks for your help.
10-29-2007 07:23 AM
It's pretty easy using the IDM, but I don't think you can do it using the CLI without knowing the sig numbers. FWIW, I don't think a service pack is going to do it either.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide