8-3
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter8 Configuring Event Action Rules
Signature Event Action Processor
Signature Event Action Processor
The Signature Event Action Processor coordinates the data flow from the signature event in the Alarm
Channel to processing through the Signature Event Action Override, the Signature Event Action Filter,
and the Signature Event Action Handler. It consists of the following components:
Alarm Channel—The unit that represents the area to communicate signature events from the
SensorApp inspection path to signature event handling.
Signature Event Action Override—Adds actions based on the risk rating value. Signature Event
Action Override applies to all signatures that fall in the range of the configured risk rating threshold.
Each Signature Event Action Override is independent and has a separate configuration value for
each action type.
Signature Event Action Filter—Subtracts actions based on the signature ID, addresses, and risk
rating of the signature event. The input to the Signature Event Action Filter is the signature event
with actions possibly added by the Signature Event Action Override.
Note
The Signature Event Action Filter can only subtract actions, it cannot add new actions.
The following parameters apply to the Signature Event Action Filter:
Signature ID
Subsignature ID
Attacker address
Attacker port
Victim address
Victim port
Risk rating threshold range
Actions to subtract
Sequence identifier (optional)
Stop-or-continue bit
Enable action filter line bit
Victim OS relevance or OS relevance
Signature Event Action Handler—Performs the requested actions. The output from the Signature
Event Action Handler is the actions being performed and possibly an evIdsAlert written to the Event
Store.
Figure 8-1 on page8-4 illustrates the logical flow of the signature event through the Signature Event
Action Processor and the operations performed on the action for this event. It starts with the signature
event with configured action received in the Alarm Channel and flows top to bottom as the signature
event passes through the functional components of the Signature Event Action Processor.