Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

MARS General FP Drop Rule vs. Listed Unconf. FPs

I have a gazillion (really!) Unconfirmed False Positive events listed on that Tab in MARS. The specific event is "Windows SMB Enum Share DoS" and I created a Drop Rule for ANY of these events, with Source and Destination from my inside networks. I know all of my systems are patched against it.

It appears my Drop Rule is working, since viewing the Sessions associated with these (clicking the "Show" link at the right of each) shows no sessions after I installed the Drop Rule.

But I still have all of these Events in the Unconf. FP list. I would like to avoid doing the "False Positive" procedure for each, for two reasons:

1. It will take a long time.

2. I will also wind up with a gazillion Drop Rules, which the system will either have to process OR I'll have to go through THEM and Inactivate them.

Any ideas?

Paul Trivino

2 REPLIES
New Member

Re: MARS General FP Drop Rule vs. Listed Unconf. FPs

Try this to prevent System Determined False Positives from displaying as incidents?

If you confirm what was previously an unconfirmed false positive, then a

drop rule is created. That drop rule should prevent any further incidents

of that type. So, this shouldn't be happening. Please make sure you've

clicked `Activate'.

Check the related bug-id:CSCsc74104

Re: MARS General FP Drop Rule vs. Listed Unconf. FPs

Sorry, System Determined False Positives is not what I was asking about, just how to get rid of the "leftover" UFP's once I've created a Drop Rule. Thanx.

Paul

94
Views
0
Helpful
2
Replies
CreatePlease login to create content