cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
686
Views
0
Helpful
2
Replies

Anomaly Detection

Guys,

I need to create my KB because the current is very very old ( 09:59:59 GMT-06:00 Tue Sep 22 2009 ) When I try to save it manually with the command

anomaly-detection vs0 save MYKB    I get an error that says:  Attack in progress

I need to create a new KB and load it because the Rotate methot is not working since the last KB is very old. I thisk it's not working because there is an attack ALWAYS.

Can I save a load a KB file manually even if there is an attack in progress?

If not, How can I fix my problem

Thanks,

DiegoCR CCSP

1 Accepted Solution

Accepted Solutions

johan.kellerman
Level 1
Level 1

Hi Diego

You can fix this by:

  1. Turn the anomaly detection off (operational-mode inactive)
  2. Erase/copy/load the files you need and start the anomaly detection or preferably put the sensor in learning accept mode (operational-mode learn) and wait for 24 hours.

Br

Johan Kellerman

View solution in original post

2 Replies 2

johan.kellerman
Level 1
Level 1

Hi Diego

You can fix this by:

  1. Turn the anomaly detection off (operational-mode inactive)
  2. Erase/copy/load the files you need and start the anomaly detection or preferably put the sensor in learning accept mode (operational-mode learn) and wait for 24 hours.

Br

Johan Kellerman

Thank you very much. I just release that I'm seeing unidirectional traffic so I will turn AD off.

Review Cisco Networking products for a $25 gift card