7-9
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter7 Defining Signatures
Configuring Signatures
Step 7
Press Enter to apply the changes or enter
no
to discard them.
Configuring Alert Severity
Use the alert-severity command in signature definition submode to configure the severity of a signature.
The following options apply:
sig_id—Identifies the unique numerical value assigned to this signature. This value lets the sensor
identify a particular signature. The value is 1000 to 65000.
subsig_id—Identifies the unique numerical value assigned to this subsignature. A subsignature ID
is used to identify a more granular version of a broad signature. The value is 0 to 255.
alert-severity—Specifies the severity of the alert:
high —Dangerous alert.
medium—Medium level alert (default).
low—Low level alert.
informational—Informational alert.
Configuring Alert Severity
To configure the alert severity, follow these steps:
Step 1
Log in to the CLI using an account with administrator or operator privileges.
Step 2
Enter signature definition submode.
sensor# configure terminal
sensor(config)# service signature-definition sig1
Step 3
Specify the signature you want to configure.
sensor(config-sig)# signatures 9000 0
Step 4
Assign the alert severity.
sensor(config-sig-sig)# alert-severity medium
Step 5
Verify the settings.
sensor(config-sig-sig)# show settings
<protected entry>
sig-id: 9000
subsig-id: 0
-----------------------------------------------
alert-severity: medium default: medium
sig-fidelity-rating: 75 <defaulted>
promisc-delta: 0 <defaulted>
sig-description
-----------------------------------------------
sig-name: Back Door Probe (TCP 12345) <defaulted>
sig-string-info: SYN to TCP 12345 <defaulted>
sig-comment: <defaulted>
alert-traits: 0 <defaulted>
release: 40 <defaulted>
-----------------------------------------------
vulnerable-os: general-os <defaulted>