cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
364
Views
0
Helpful
3
Replies

Not able to filter alters on my IDSM

wadeski
Level 1
Level 1

I am getting a large amounts of IP Fragment alerts from one ip address. I have identified this as a false positive and want to filter these events. I have gone into the filter tab on the IDSM and filtered alter 1003 Ip Fragmentation from the source ip that is generating all the alters. I save and update and push the new config to the idsm without any problems, but I keep getting the alters. I also set the alert to LOW and it is still registering as high. Am I missing something? Thanks in advance.

3 Replies 3

murabi
Level 4
Level 4

Try setting the alert to “Information”. This categorizes the attack as not being relevant to security while “Low” categorizes the attack as mildly severe.

Are you using CSPM or Unix Director.

If you are using Unix Director you may be seeing old alerts.

Look in the /usr/nr/var directory on your director for an nrdirmap buffer file.

If there are too many alarms in OV then the extra wind up in this file.

When ever you start "ovw" it will read in these old buffered alarms.

You could be see old alarms from this buffer file.

wadeski
Level 1
Level 1

OK, I figured it out. I have my CSPM set in a client/server configuration. I upgraded the CSPM on the server to CSPM-2.3.3i-S25 and did the signature update wizard on the server. However, I did not perform this on my client. When I pushed configs from my client I had to select ***S13 because I had not updated the signatures on my client. This also did not allow me to add filters or do any maintenance for that matter on any of my blades.

After installing CSPM-2.3.3i-S25 on my client and running signature wizard I was able to set filters with no issues. Thanks for your responses.