7-10
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter 7 Defining Signatures
Configuring Signatures
engine
-----------------------------------------------
atomic-ip
-----------------------------------------------
event-action: produce-alert <defaulted>
fragment-status: any <defaulted>
specify-l4-protocol
-----------------------------------------------
--MORE--
Step 6
Exit signatures submode.
sensor(config-sig-sig)# exit
sensor(config-sig)# exit
Apply Changes:?[yes]:
Step 7
Press Enter to apply the changes or enter
no
to discard them.
Configuring the Event Counter
Use the event-counter command in signature definition submode to configure how the sensor counts
events. For example, you can specify that you want the sensor to send an alert only if the same signature
fires 5 times for the same address set.
The following options apply:
event-count—Specifies the number of times an event must occur before an alert is generated. The
valid range is 1 to 65535. The default is 1.
event-count-key—Specifies the storage type on which to count events for this signature:
Axxx—Attacker address
AxBx—Attacker and victim addresses
Axxb—Attacker address and victim port
xxBx—Victim address
AaBb—Attacker and victim addresses and ports
specify-alert-interval [yes | no]—Enables alert interval:
alert-interval—Specifies the time in seconds before the event count is reset. The default is 60.
Configuring the Event Counter
To configure event counter, follow these steps:
Step 1
Log in to the CLI using an account with administrator or operator privileges.
Step 2
Enter signature definition submode.
sensor# configure terminal
sensor(config)# service signature-definition sig1
Step 3
Specify the signature for which you want to configure event counter.
sensor(config-sig)# signatures 9000 0