cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
209
Views
4
Helpful
1
Replies

5160 passing Event filters?

DSmirnov
Level 1
Level 1

Sorry for another complaint but today I've got signature 5160 fired:

205.150.179.NN <- 208.51.1.102 (5160) Intrusion alert: 5160 Apache ? indexing file disclosure bug

same time I have 5160 filtered for this specific IP on IDS sensor:

5160 * False * 205.150.179.M,205.150.179.NN

Is it possible? I'm little worried since I heavely build my IDS processing on sensor filters.

1 Reply 1

mjuckett
Level 1
Level 1

I had the same problem with that exact signature. I opened a TAC case on it. Eventually his suggestion was change the filter to Any > Any and push the config out. Then I changed it back to my original filter and pushed that configuration out. Afterwards, my filter worked fine. Perhaps trying this might work for you.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: