Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Community Member

Secmon quits reporting triggered events

It seems that when I update a sensor, be it through deploying modifications or signature updates, that I have to go through a whole new process to get SECMON to start reporting again.

I know it takes some time for signature updates to start reporting again and it is wise to stop the sniffing interface if the sensor is really busy, but how long is long. Is there a set amount of time I should wait? Also, is there something I can do to speed the process up. Obviously this is not something I should do in the evening when we are attempting to halt suspicious activity.

Any ideas?

Thanks

Dwane

1 REPLY
Silver

Re: Secmon quits reporting triggered events

I believe it takes some time for signature updates to start repoirting again and this time cannot be reduced.

84
Views
0
Helpful
1
Replies
CreatePlease to create content