cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
398
Views
0
Helpful
3
Replies

Event ID for "Sudden increase of traffic to a port" - MARS

cniblo1975
Level 1
Level 1

Hi. I'm having trouble with "Sudden increase of traffic to a port" rule not firing. I think there is an issue with the event itself. I'd like to verify the event ID and groups associated with it. Can someone please provide me with this info? Thanks!

Christine

3 Replies 3

vkapoor5
Level 5
Level 5

did you change status for this original system rule to INACTIVE and now it's just not showing up when you view only the ACTIVE rules

Nope, I duplicated it and it blew out the original rule! After I duplicated it, I could no longer find the original one. The rule shows up as a user rule, the duplicate I created. And it doesn't appear to be working.

I just realized I posted this under the VPN section. Don't know what I was thinking (wasn't, obviously). I'll repost under general security. Thanks!