Hi,
I am trying to setup a custom alarm for DOS attacks, as we do not have any devices that support flows so the DOS content pack doesnt work for it.
I have configured an alarm to for a signature ID a count of 1000 and an elapsed timeframe of 60(which Im assuming is 60 seconds?).
I cannot get this rule to fire, any help would be appreciated.
Thanks,
KJoyal
Remove the last two conditions, and try to add a threshold via the 3 dots in front of the AND operator, define number of events and time period.
The only thing I can do with the with the 3 dots in front of the AND is change it to a OR statement.
that's strange. Do you not have Threshold and Time Window option when you edit logical element? Maybe you are on alarm, can you create a correlation rule instead?
Hi.
1- sssyyyy is right. your in the FIeld MATCH GUI in the Alarm section
you need to add a correlation for that, there you could set the time fram ETC just by clicking on the "AND" gate.
regarding the signature ID you added, what is the rule name of that signature?
maybe there is the problom.
Best Regards👍👍👍
David
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA