Hi all,
I did hit a false positive alarm today: a wireless AP was a source of 'suspect data hoarding' from a WLC.
I wanted to disable this core event in this case, but not sure what would be the best way to do so.
Ideally, I want to disable this event only for traffic between AP and WLC host groups, but that isn’t possible it seems?
As an alternative I could create a custom core event for 'suspect data hoarding', where I assign the WLC group as 'host' and I configure 'when host is target' to 'Off'.
Would this have the desired effect? (As it is not alerting on the WLC as target, but on the AP as source).
I don't want to disable this event on the AP group as source, since I want to be alterted if I see this behaviour towards any other destination.
Last option I can think of is to create a custom service for CAPWAP data and turn on 'exclude security event', then on the AP host group also turn on 'disable security events using excluded services'.
Thanks for any advice on this!