cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
228
Views
0
Helpful
1
Replies

Custom Signature

dblairii
Level 1
Level 1

I have certain routers that I want to monitor. However, rather than being alarmed only certain traffic, I want to be notified when there is traffic to/from the device that is NOT SNMP(161) or Syslog(514). Is this possible and is it practical?

I am not sure how to create a signature to do this. Can anyone help?

1 Reply 1

mcerha
Level 3
Level 3

Signature 4508 will detect non-SNMP traffic on UDP port 161. We don't currently have a signature for detecting non-syslog traffic on UDP port 514 though. This will need a non-trivial signature requiring some development work. If you feel strongly that this is needed, please file an ehancement request via your account representative or the TAC.