cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
683
Views
0
Helpful
2
Replies

Anomaly Detection

Guys,

I need to create my KB because the current is very very old ( 09:59:59 GMT-06:00 Tue Sep 22 2009 ) When I try to save it manually with the command

anomaly-detection vs0 save MYKB    I get an error that says:  Attack in progress

I need to create a new KB and load it because the Rotate methot is not working since the last KB is very old. I thisk it's not working because there is an attack ALWAYS.

Can I save a load a KB file manually even if there is an attack in progress?

If not, How can I fix my problem

Thanks,

DiegoCR CCSP

1 Accepted Solution

Accepted Solutions

johan.kellerman
Level 1
Level 1

Hi Diego

You can fix this by:

  1. Turn the anomaly detection off (operational-mode inactive)
  2. Erase/copy/load the files you need and start the anomaly detection or preferably put the sensor in learning accept mode (operational-mode learn) and wait for 24 hours.

Br

Johan Kellerman

View solution in original post

2 Replies 2

johan.kellerman
Level 1
Level 1

Hi Diego

You can fix this by:

  1. Turn the anomaly detection off (operational-mode inactive)
  2. Erase/copy/load the files you need and start the anomaly detection or preferably put the sensor in learning accept mode (operational-mode learn) and wait for 24 hours.

Br

Johan Kellerman

Thank you very much. I just release that I'm seeing unidirectional traffic so I will turn AD off.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card