8-4
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter8 Configuring Event Action Rules
Event Actions
Figure 8-1 Signature Event Through Signature Event Action Processor
For More Information
For more information on risk rating, see Calculating the Risk Rating, page 8-13.
Event Actions
The IPS has the following event actions:
Alert and Log Actions
produce-alert—Writes the event to the Event Store as an alert.
Note
The produce-alert action is not automatic when you enable alerts for a signature. To have an
alert created in the Event Store, you must select produce-alert. If you add a second action,
you must include produce-alert if you want an alert sent to the Event Store. Also, every time
you configure the event actions, a new list is created and it replaces the old list. Make sure
you include all the event actions you need for each signature.
Consumed
signature event
132188
Signature event with
configured action
Signature event
Add action based on RR
Subtract action based on
signature, address, port, RR, etc.
Subtract action based on
current summary mode
Perform action
Event count
Signature event
action override
Signature event
action filter
Signature event
summary filter
Signature event
action handler