Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Community Member

Missing context for signature 5081

I have two sensors running on the same level. One records the context for signature 5081 the other only the event without any more informations.

For example:

4,1220191,2002/09/30,19:12:36,2002/09/30,19:12:36,10008,20300,908,OUT,IN,4,5081,0,TCP/IP,XXXXXXXXXXXXX,XXXXXXXXXXXXX,412

3,80,0.0.0.0,/system32/cmd.exe,474554202F736372697074732F2E2E25323535632E2E2F77696E6E742F73797374656D33322F636D642E6578653F2F632B64697220485454502F312E300DZZ

(GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0)

the other system does record only

4,1006597,2002/09/18,05:19:17,2002/09/18,05:19:17,10008,201

00,908,OUT,IN,1,5081,0,TCP/IP,XXXXXXXXX,XXXXXXXXX,4636,80,0.0.0.0,/system

32/cmd.exe

We need this information, because we include it in our daily reports, just to see if somebody is only probing (dir...) or tries something else. Is there any switch / parameter that is controlling the recording of context information ? I checked the settings within the .SizWizMenu program, and both maschines are using the same definitions.

3 REPLIES
Cisco Employee

Re: Missing context for signature 5081

Please describe each sensor, model #, software version, Sig Update version.

There is no switch to turn it on. It should be there. Are the two sensors Identical? (i.e. both 4230's running 3.1.3 S32 )

Cisco Employee

Re: Missing context for signature 5081

There is not a switch in packetd, but there is one for loggerd.

Try looking in loggerd.conf for the token MinContextLevel.

Normally this is set to 2 so level 2 alarms and higher will have their Context logged, but if you accidentally changed this to 5 then your level 4 alarm being generated will not have it's Context information logged in the sensor log file.

Community Member

Re: Missing context for signature 5081

Great - the event level was below of the MinContextLevel. I adjusted it and voila its working.

Thank you very much...

Peter

124
Views
5
Helpful
3
Replies
CreatePlease to create content