Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Cipriano
Contributor

Smart Event IPS problem

Smart event is OK, I can see that it has collected all the logs, less than IPS, when going in the smart log I can see that there are several IPS logs, but I can not see through Smart Event. I see applications, url, virus and bot! but ips is blank.

Labels (1)
5 Replies
PhoneBoy
Admin
Admin

What version of SmartEvent? (With applied hotfixes)

0 Kudos
Cipriano
Contributor

77.30

0 Kudos
PhoneBoy
Admin
Admin

Are you using the NGSE version of SmartEvent or just R77.30?

Also what patch level (as requested)?

It would also be helpful to see screenshots of where you are expecting to see the events and what's actually showing.

Might also check the following: SmartEvent / Eventia Analyzer stopped showing new events on the 'Events' tab in the SmartE... 

0 Kudos
Cipriano
Contributor

GAIA 77.30 on VMware.

You see the IPS bullets no information

0 Kudos
PhoneBoy
Admin
Admin

I guess I'm still not understanding what you're expecting to see and not seeing.

In the first screenshot, you posted the list of IPS events that occurred).

Going to include that here to make the thread easier to follow:

In the second screenshot, there are two timelines that mention IPS.

Again, including it below to make the thread easier to follow.

  • "IPS Most Important Not Prevented" means IPS signatures that were triggered but are set in Detect Mode. This could easily be zero depending on what signatures were triggered.
  • "IPS Follow Up" means IPS signatures that were triggered that are tagged for followup. Again, this could easily be zero depending on what signatures were triggered.

Important Security Events will also include IPS events.

0 Kudos