cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
300
Views
0
Helpful
3
Replies

VMS Suggestion - Custom Sigs and Sig Upgrades

- In VMS when you upgrade the Sigs if you have done any modification to a General Signature's Signature Engine. The mods are not save to the upgraded version. It would be nice if changes to a General Sig was saved to your Custom Sigs.

- The other thing is for Custom Sigs if I am managing 100(s) of sensors and add a Custom Sig to a sensor it only does it for that 1 sensor. I have to build another sig to all the sensors manually if I do not want to corrupt my other Custom/General Sigs on my other devices.

3 Replies 3

nikhil_m
Level 1
Level 1

For your second question, that is how it should work

picketfence
Level 1
Level 1

We conquer your distrubution problem by having two sensors: a 3.X and a 4.X that sit unplugged from sniffing. They act strictly as "distribution" sensors and we tune sigs from there, then copy them to corresponding sites. This seems to work pretty well.

Cheers,

Ben

Hi,

Can you not do the same by just have a couple of dummy sensor definitions in VMS and copy the configs out from there ?

I suspect you have the actual sensors to test the signatures too ?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: