Alert Frequency - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

MASTER Engine
Table B-1
Table B-1
Parameter
alert-severity
engine
event-counter
event-count
event-count-key
specify-alert-interval Enables alert interval.
alert-interval
promisc-delta
sig-fidelity-rating
sig-description
sig-name
sig-string-info
sig-comment
alert-traits
release
status

Alert Frequency

The purpose of the alert frequency parameter is to reduce the volume of the alerts written to the Event
Store to counter IDS DoS tools, such as stick. There are four modes: Fire All, Fire Once, Summarize,
and Global Summarize. The summary mode is changed dynamically to adapt to the current alert volume.
For example, you can configure the signature to Fire All, but after a certain threshold is reached, it starts
summarizing.
Table B-2 on page B-5
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
B-4
lists the general master engine parameters.
MASTER Engine General Parameters
Description
Severity of the alert:
Dangerous alert
Medium-level alert
Low-level alert
Informational alert
Specifies the engine the signature belongs to.
Grouping for event count settings.
Number of times an event must occur before an alert is
generated.
The storage type on which to count events for this signature:
Attacker address
Attacker and victim addresses
Attacker address and victim port
Victim address
Attacker and victim addresses and ports
Time in seconds before the event count is reset.
Delta value used to determine seriousness of the alert.
Rating of the fidelity of this signature.
Grouping for your description of the signature.
Name of the signature.
Additional information about this signature that will be
included in the alert message.
Comments about this signature.
Traits you want to document about this signature.
The release in which the signature was most recently updated. release
Whether the signature is enabled or disabled, active or retired. enabled
lists the alert frequency parameters.
Appendix B
Signature Engines
Value
high
medium
low
informational
1 to 65535
Axxx
AxBx
Axxb
xxBx
AaBb
yes | no
2 to 1000
0 to 30
0 to 100
sig-name
sig-string-info
sig-comment
0 to 65335
retired
78-16527-01

Advertisement

Table of Contents
loading

Table of Contents