Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
jcallahan
Explorer

SmartEvent alerting on logs that don't match filter?

I have defined some events in SmartEvent to get alerted when IPS sees traffic that matches a protection that is still staged and not prevented. However, I am getting alerted on traffic that appears to have been prevented by the blade. That does not match what I put in the filter. Any insight on why the traffic is generating an event? I have attached a sample traffic and my defined event.

 

 

3 Replies
PhoneBoy
Admin
Admin

Are both of those IPS events generating alerts?
We would have to see the log card on both to comment further (mask sensitive data if required).

jcallahan
Explorer

I believe just the correlated log is the one firing off the alert. It makes sense to me that the severity is 4 and the action is blank, so therefore it is NOT prevent. That would make it match the criteria that SmartEvent is looking for. If that's the case, I might have to filter out correlated logs.

PhoneBoy
Admin
Admin

That also makes sense to me as well. 

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events