- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: SmartEvent alerting on logs that don't match f...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SmartEvent alerting on logs that don't match filter?
I have defined some events in SmartEvent to get alerted when IPS sees traffic that matches a protection that is still staged and not prevented. However, I am getting alerted on traffic that appears to have been prevented by the blade. That does not match what I put in the filter. Any insight on why the traffic is generating an event? I have attached a sample traffic and my defined event.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Are both of those IPS events generating alerts?
We would have to see the log card on both to comment further (mask sensitive data if required).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I believe just the correlated log is the one firing off the alert. It makes sense to me that the severity is 4 and the action is blank, so therefore it is NOT prevent. That would make it match the criteria that SmartEvent is looking for. If that's the case, I might have to filter out correlated logs.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That also makes sense to me as well.
