cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
463
Views
0
Helpful
3
Replies

CS-MARS : Inactive User-Defined Rules/Drop Rules/False Positive

a.kiprawih
Level 7
Level 7

Hi,

I have created dummy rules to drop any events that is rated as normal activities such as when switch interface status changed to up/down everytime users on/off their PCs, or when firewall translation is expired once the connectivity/sessions is terminated. Same goes to false positives where MARS will either drop or logged the events for any events matched with the customized rules.

However, when I changed the dummy rules to 'inactive' so that MARS will log and display everything back to normal, the status displayed on the main page under "Drop" is still increased. Now, no events are displayed on the main screen like before.

Any suggestions/help?

Thanks

AK

3 Replies 3

s.jankowski
Level 4
Level 4

Hey, check the link for "HOW QUERY, REPORTS, AND RULES WORK" this will provide a idea

http://www.cisco.com/en/US/products/ps6241/products_qanda_item0900aecd802b7c6b.shtml

a.kiprawih
Level 7
Level 7

This was due to a bug (CSCsc31386) in CS-MARS database on v3.4.1. It was fixed by loading v4.1.1.

Rgds,

AK

Correction - it was v4.1.2, not v4.1.1

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: