Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

5160 passing Event filters?

Sorry for another complaint but today I've got signature 5160 fired:

205.150.179.NN <- 208.51.1.102 (5160) Intrusion alert: 5160 Apache ? indexing file disclosure bug

same time I have 5160 filtered for this specific IP on IDS sensor:

5160 * False * 205.150.179.M,205.150.179.NN

Is it possible? I'm little worried since I heavely build my IDS processing on sensor filters.

1 REPLY
New Member

Re: 5160 passing Event filters?

I had the same problem with that exact signature. I opened a TAC case on it. Eventually his suggestion was change the filter to Any > Any and push the config out. Then I changed it back to my original filter and pushed that configuration out. Afterwards, my filter worked fine. Perhaps trying this might work for you.

84
Views
4
Helpful
1
Replies