MASTER Engine
Table B-1
Table B-1
Parameter
alert-severity
engine
event-counter
event-count
event-count-key
specify-alert-interval Enables alert interval.
alert-interval
promisc-delta
sig-fidelity-rating
sig-description
sig-name
sig-string-info
sig-comment
alert-traits
release
status
Alert Frequency
The purpose of the alert frequency parameter is to reduce the volume of the alerts written to the Event
Store to counter IDS DoS tools, such as stick. There are four modes: Fire All, Fire Once, Summarize,
and Global Summarize. The summary mode is changed dynamically to adapt to the current alert volume.
For example, you can configure the signature to Fire All, but after a certain threshold is reached, it starts
summarizing.
Table B-2 on page B-5
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
B-4
lists the general master engine parameters.
MASTER Engine General Parameters
Description
Severity of the alert:
•
Dangerous alert
Medium-level alert
•
Low-level alert
•
Informational alert
•
Specifies the engine the signature belongs to.
Grouping for event count settings.
Number of times an event must occur before an alert is
generated.
The storage type on which to count events for this signature:
Attacker address
•
Attacker and victim addresses
•
Attacker address and victim port
•
Victim address
•
Attacker and victim addresses and ports
•
Time in seconds before the event count is reset.
Delta value used to determine seriousness of the alert.
Rating of the fidelity of this signature.
Grouping for your description of the signature.
Name of the signature.
Additional information about this signature that will be
included in the alert message.
Comments about this signature.
Traits you want to document about this signature.
The release in which the signature was most recently updated. release
Whether the signature is enabled or disabled, active or retired. enabled
lists the alert frequency parameters.
Appendix B
Signature Engines
Value
high
medium
low
informational
—
—
1 to 65535
Axxx
AxBx
Axxb
xxBx
AaBb
yes | no
2 to 1000
0 to 30
0 to 100
—
sig-name
sig-string-info
sig-comment
0 to 65335
retired
78-16527-01
Need help?
Do you have a question about the 4215 - Intrusion Detection Sys Sensor and is the answer not in the manual?
Questions and answers