Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 
Community Member

About filter of signature

We use CSPM(ver2.5i) and CSIDS(ver2.2.1.8) now.

Although I want to configure filter of whole signature by Source IP address unit. I look like that We can configure filter for each signature on CSPM and We can't filter with Source IP address unit. If possible it, Please tell me how to configure. or Can be this function fixed by applying CSPM and CSIDS Patch?

Cisco Employee

Re: About filter of signature

This feature is available in the sensor V2.5 and above.

You will need to upgrade to CSPM 2.3.1i and the latest sensor version 2.5(1)S3.

Then use the Epilogue Feature in CSPM to add RecordOfExcludedPattern lines to exclude the signatures that you want.

The Epilogue Feature directions are explained in:

The RecorOfExcludedPatterns are described in:

So you could use the Epilogue feature to add the following RecordOfExcludedPatterns for example:

RecordOfExcludedPattern * * *

RecordOfExcludedPattern 2100,3050 *,

NOTE: Ordinarily this would be done using the AdvancedFilter Tab in the CSPM configuration area, but there is a bug in CSPM that causes a "0" instead of the "*" to be used in the field for the subsignature. Once this is fixed in CSPM then you would be able to use the AdvancedFilter Tab instead of the Epilogue feature to configure the excludes.

CreatePlease to create content