09-24-2004 02:03 AM - edited 03-09-2019 08:53 AM
I've updated signatures using IDS-sig-4.1-4-S114.rpm.pkg. After it i see that Signature's group S106-S114 is empty. I'm little misunderstood - why i must to upgrade signatures and get empty signature's groups?
09-30-2004 08:40 AM
Well the reason that I could think of is either they came up with a better Signature which has replaced these or these were false alarms to start with.
09-30-2004 10:40 AM
There are definately new signatures in most of these S levels (View the S117 readme file to a see a list of the signatures included in each Signature Update).
http://ftp-sj.cisco.com/cisco/ciscosecure/ids/sigup/4.x/IDS-sig-4.1-4-S117.readme.txt
It sounds like there is something in the user interface that may be grouping the signature according to their Sig level. This grouping is based off a system configuration file, and my guess is that when the signatures were added that somebody (one of our engineers) forgot to update that system configuration file.
If you can tell us exactly where you are looking for the Signature Groups S106-S114 (which User Interface progam, and exactly which screen).
Then we can see which configuration file is being used for that information, and see if it is being updated.
Also please try to load the latest S117, the issue may have already been addressed in a later sig update.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide