cancel
Showing results for 
Search instead for 
Did you mean: 
Post a Question

Smart Event IPS problem

Smart event is OK, I can see that it has collected all the logs, less than IPS, when going in the smart log I can see that there are several IPS logs, but I can not see through Smart Event. I see applications, url, virus and bot! but ips is blank.

Labels (1)
5 Replies
Admin
Admin

Re: Smart Event IPS problem

What version of SmartEvent? (With applied hotfixes)

0 Kudos

Re: Smart Event IPS problem

77.30

0 Kudos
Admin
Admin

Re: Smart Event IPS problem

Are you using the NGSE version of SmartEvent or just R77.30?

Also what patch level (as requested)?

It would also be helpful to see screenshots of where you are expecting to see the events and what's actually showing.

Might also check the following: SmartEvent / Eventia Analyzer stopped showing new events on the 'Events' tab in the SmartE... 

0 Kudos

Re: Smart Event IPS problem

GAIA 77.30 on VMware.

You see the IPS bullets no information

0 Kudos
Admin
Admin

Re: Smart Event IPS problem

I guess I'm still not understanding what you're expecting to see and not seeing.

In the first screenshot, you posted the list of IPS events that occurred).

Going to include that here to make the thread easier to follow:

In the second screenshot, there are two timelines that mention IPS.

Again, including it below to make the thread easier to follow.

  • "IPS Most Important Not Prevented" means IPS signatures that were triggered but are set in Detect Mode. This could easily be zero depending on what signatures were triggered.
  • "IPS Follow Up" means IPS signatures that were triggered that are tagged for followup. Again, this could easily be zero depending on what signatures were triggered.

Important Security Events will also include IPS events.

0 Kudos