Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Paulo_Balau
Contributor

SmartEvent does not capture IPS events

Hello All...

I'm trying to set up an email alert for every IPS log with action prevent and/or severity critical.

After proper capturing I whish to block the source for, say, 8 hrs. BUT, as hard as I tried, I cannot capture severity field!

When I try to use Severity Equal to Critical it never captures the event... Tried other fields, such as attack ID or attack name and I alway got no reaction as well...

Versions I have are R80.30 for SmartConsole and SmartEvent.

So, Detailing...

Read somewhere around here I should have "Generic IPS Event" active. I set it, and I set a email reaction.

In fact, only after this ticked I started capturing events but never received an email for this "Generic IPS Event".

Geeneric.png

User defined event, "IPSActionEvent" is defined as follows and seems to work 🙂

Product I use from list is IPS Software Blade...

event1.PNG

I got emails for this "User defined Event | IPSActionEvent" BUT only when I place action equal to prevent.

Here snaphots from logs...

correlates.PNG

Seemed ok until now BUT 😞 When I try to use Severity Equal to Critical it never captures the event...

Tried other field, as attack ID or attack name and I alway got no reaction.

Event2.PNG

I wonder why?

 

Any help is welcomed

 

Best Regards,

Paulo Balau

 

 

 

0 Kudos
2 Replies
the_rock
Advisor

I know this is a long shot, but I fixed similar issue before with evstop/evstart...

0 Kudos
Paulo_Balau
Contributor

Hi! Nope! We've updated 80.30 to latest buils & rebooted everything... Unfortonately I got same results.

0 Kudos