cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
396
Views
0
Helpful
2
Replies

Signature update

rmv72
Level 1
Level 1

I've updated signatures using IDS-sig-4.1-4-S114.rpm.pkg. After it i see that Signature's group S106-S114 is empty. I'm little misunderstood - why i must to upgrade signatures and get empty signature's groups?

2 Replies 2

thomas.chen
Level 6
Level 6

Well the reason that I could think of is either they came up with a better Signature which has replaced these or these were false alarms to start with.

marcabal
Cisco Employee
Cisco Employee

There are definately new signatures in most of these S levels (View the S117 readme file to a see a list of the signatures included in each Signature Update).

http://ftp-sj.cisco.com/cisco/ciscosecure/ids/sigup/4.x/IDS-sig-4.1-4-S117.readme.txt

It sounds like there is something in the user interface that may be grouping the signature according to their Sig level. This grouping is based off a system configuration file, and my guess is that when the signatures were added that somebody (one of our engineers) forgot to update that system configuration file.

If you can tell us exactly where you are looking for the Signature Groups S106-S114 (which User Interface progam, and exactly which screen).

Then we can see which configuration file is being used for that information, and see if it is being updated.

Also please try to load the latest S117, the issue may have already been addressed in a later sig update.