cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
431
Views
0
Helpful
1
Replies

Metacomponents

adam_smith
Level 1
Level 1

I have my IPS reporting to MARS and I am currently getting a lot of events that are being caused by metacomponents. It is my understanding that these metacomponents should not be producing any events/alerts.

This is occurring with a number of signatures. Have doubled checked that the signatures are in their default state with no actions defined.

Anyone know where I should start looking or is this the correct behavior.

1 Reply 1

Not applicable

One of the signature engine of IPS 6.0 is Meta engine.

Meta-Defines events that occur in a related manner within a sliding time interval. This engine processes events rather than packets. As signature events are generated, the Meta engine inspects them to determine if they match any or several Meta definitions. The Meta engine generates a signature event after all requirements for the event are met.

All signature events are handed off to the Meta engine by SEAP. SEAP hands off the event after processing the minimum hits option. Summarization and event action are processed after the Meta engine has processed the component events.

But the large number of Meta signatures could adversely affect overall sensor performance. You can remove the actions as metacomponents are not to be edited.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card