On my 4240 and IDSM2 IPS I tried applying an event action filter to filter this sig from firing from internal IPs and going to internal IPs on all ports. The signature is still being reported to my respective MARS boxes. I've tried different combinations of internal IP addresses and the filter still won't work. I've also moved the filter up to the first position in the list. This is the only filter out of dozens that does not work, btw.
Has anyone else encountered a similar problem or have a possible solution?
I think I know what is happening. Remember, the event action filters are simply removing actions for the alarm. This particular alarm contains a few destination IP addresses outside your filter, so the actions aren't being removed.