Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Scott_Paisley
Collaborator

Anti-virus signature not found

Jump to solution

We have logs indicating an anti-virus signature detected something, but didn't prevent it.

I want to change the action to drop, but I can't find the signature

What am I doing wrong?

0 Kudos
1 Solution

Accepted Solutions
Timothy_Hall
Champion
Champion

Was starting to suspect this was a cloud-based detection of something new for which no signature had been propagated yet, but as it turns out you can't find it in the SmartConsole now because it has been removed in an update, from the ThreatWiki: 

gone.png 

 

New 2021 IPS/AV/ABOT Self-Guided Video Series
now available at http://www.maxpowerfirewalls.com

View solution in original post

8 Replies
Timothy_Hall
Champion
Champion

Need to see the full log card for this log entry with IP addresses redacted.

New 2021 IPS/AV/ABOT Self-Guided Video Series
now available at http://www.maxpowerfirewalls.com
0 Kudos
Scott_Paisley
Collaborator

attached

0 Kudos
Timothy_Hall
Champion
Champion

Please fully expose (with redaction as needed) all areas of the log card that have a caret "^" pointing downwards.  Can't even tell if it is Anti-bot or Anti-virus with that screenshot.

New 2021 IPS/AV/ABOT Self-Guided Video Series
now available at http://www.maxpowerfirewalls.com
0 Kudos
Scott_Paisley
Collaborator

anti-virus

0 Kudos
G_W_Albrecht
Legend
Legend

I would suggest to change all detect to prevent - its the same resources spent but no action taken (except a log) with detect.

But better contact TAC about this...

0 Kudos
Scott_Paisley
Collaborator

that's what I want to do, but I can't find the protection to make that change

0 Kudos
Timothy_Hall
Champion
Champion

Was starting to suspect this was a cloud-based detection of something new for which no signature had been propagated yet, but as it turns out you can't find it in the SmartConsole now because it has been removed in an update, from the ThreatWiki: 

gone.png 

 

New 2021 IPS/AV/ABOT Self-Guided Video Series
now available at http://www.maxpowerfirewalls.com

View solution in original post

Scott_Paisley
Collaborator

OK, thanks

0 Kudos