cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
361
Views
0
Helpful
3
Replies

Including a packet decode with signature alarm

mjohnson
Level 1
Level 1

Is there a way to include the first 64 bytes of a packet in the alarm message for a particular signature?

3 Replies 3

mhellman
Level 7
Level 7

You can include the entire trigger packet by adding the 'produce verbose alert' action to a signature. Specific engines include a certain amount of "contextual" data but it's not documented which do and how much.

Thats great thanx, for packet capture I can use "IP logging".

Mike j

or you can add the 'log pair packets' action to a specific signature. The caveat however is that the capture starts with the trigger packet.

Review Cisco Networking products for a $25 gift card