Alerts are LOST somewhere in Action Override Stage...

I have very, very strange statistics on my sensor. I cleared it few minutes ago and now it is as follows:
SigEvent Preliminary Stage Statistics
Number of Alerts received = 60
Number of Alerts Consumed by AlertInterval = 0
Number of Alerts Consumed by Event Count = 0
Number of FireOnce First Alerts = 0
Number of FireOnce Intermediate Alerts = 0
Number of Summary First Alerts = 8
Number of Summary Intermediate Alerts = 43
Number of Regular Summary Final Alerts = 8
Number of Global Summary Final Alerts = 0
Number of Active SigEventDataNodes = 10
Number of Alerts Output for further processing = 60
SigEvent Action Override Stage Statistics
Number of Alerts received to Action Override Processor = 60
Number of Alerts where an override was applied = 0
Actions Added
deny-attacker-inline = 0
deny-attacker-victim-pair-inline = 0
deny-attacker-service-pair-inline = 0
deny-connection-inline = 0
deny-packet-inline = 0
modify-packet-inline = 0
log-attacker-packets = 0
log-pair-packets = 0
log-victim-packets = 0
produce-alert = 0
produce-verbose-alert = 0
request-block-connection = 0
request-block-host = 0
request-snmp-trap = 0
reset-tcp-connection = 0
request-rate-limit = 0
SigEvent Action Filter Stage Statistics
Number of Alerts received to Action Filter Processor = 0
Number of Alerts where an action was filtered = 0
Number of Filter Line matches = 0
Number of Filter Line matches causing decreased DenyPercentage = 0
Actions Filtered
deny-attacker-inline = 0
deny-attacker-victim-pair-inline = 0
deny-attacker-service-pair-inline = 0
deny-connection-inline = 0
deny-packet-inline = 0
modify-packet-inline = 0
log-attacker-packets = 0
log-pair-packets = 0
log-victim-packets = 0
produce-alert = 0
produce-verbose-alert = 0
request-block-connection = 0
request-block-host = 0
request-snmp-trap = 0
reset-tcp-connection = 0
request-rate-limit = 0
SigEvent Action Handling Stage Statistics.
Number of Alerts received to Action Handling Processor = 1
Number of Alerts where produceAlert was forced = 0
Number of Alerts where produceAlert was off = 0
Actions Performed
deny-attacker-inline = 0
deny-attacker-victim-pair-inline = 0
deny-attacker-service-pair-inline = 0
deny-connection-inline = 0
deny-packet-inline = 0
modify-packet-inline = 0
log-attacker-packets = 0
log-pair-packets = 0
log-victim-packets = 0
produce-alert = 1
produce-verbose-alert = 0
request-block-connection = 0
request-block-host = 0
request-snmp-trap = 0
reset-tcp-connection = 0
request-rate-limit = 0
Per-Signature SigEvent count since reset
Sig 60000.0 = 1
Yes, single signature fired, but the number of "Preliminary Stage Alerts" was 60 !? What happened with other 59 alerts ???

Only when the alert has at least one action will it be passed to the event action handler.
So the other 59 alerts did not have any event action. Either no action was added directly from the signature definition, or the alerting type actions were removed because of summarization, or the actions were removed by filters.
There are several signatures that are intentionally created without actions. These signatures are what we call meta component signatures. On their own they don't mean much and so we remove all actions and they do not generate alerts into the eventstore. They trigger internally in sensorApp but do not get written to the eventstore. These alerts are internally monitored by Meta signatures. When multiple component signatures are triggered, then a Meta signature may trigger and it is the Meta signature that would have a produce-alert event action and be written to the eventStore.
With summarization the signature has a produce-alert action, but the summarizer routines see that the signature is being triggered multiple times with same addresses. The summarizer will allow through an alert on the first triggering. Later triggerings with the same address set will cause the summarizer to automatically remove the produce-alert action (and other alert causing actions). So the summarized alerts will not get written to the eventStore.
NOTE: In your output this happened for at least 43 of these alerts.
Filters may also be matching the alerts, and the filters may be removing the event actions.
So if the event actions have all be removed (or none were ever added), then the alert will not be passed to the event action handler.
In your output only 1 of the 60 alerts wound up with any actions needing to be executed.

Similar Messages

  • Loading web pages from many sites do not work, most sorcecode are lost somewhere

    In win XP installing Oracle virtualbox os=suselinux + firefox 3.6.10 all
    webpages works!
    But, on win XP firefox 9.0.1. many web pages only last html source
    code are visible in the webpage. Mozilla support only avaible inside in the WM-box on old firefox!!!
    To hard to remove plugins, fix it!!
    Disable of all plugins, more wegpages work, but not all!!
    Iam using telenor mobile internet, ASUS mb, amd2, XP 2002 service pack 3. On two computers, same errors!
    Have done 3 reinstallations of firefox 9.0.1 , still not work!

    In win XP installing Oracle virtualbox os=suselinux + firefox 3.6.10 all
    webpages works!
    But, on win XP firefox 9.0.1. many web pages only last html source
    code are visible in the webpage. Mozilla support only avaible inside in the WM-box on old firefox!!!
    To hard to remove plugins, fix it!!
    Disable of all plugins, more wegpages work, but not all!!
    Iam using telenor mobile internet, ASUS mb, amd2, XP 2002 service pack 3. On two computers, same errors!
    Have done 3 reinstallations of firefox 9.0.1 , still not work!

  • Why do I get a "can't import spreadsheet because it was created with an unsupported application version" alert when the updated version was purchased direct from the Mac App Store? The spreadsheet is now lost somewhere!

    Why do I get a "can't import spreadsheet because it was created with an unsupported application version" alert when the updated version was purchased direct from the Mac App Store? The spreadsheet is now lost somewhere!

    Pages 4.3 should still be in an iWorks folder within your Applications folder. 
    http://www.apple.com/feedback/pages.html

  • Sync between MacBookPro and iPhone 3G does not sync properly.  Calendars duplicate events but worse is that only contacts from Address book from letter T onwards sync.  Any contacts on iPhone which are not on Mac are lost during sync.

    Sync between MacBookPro and iPhone 3G does not sync properly.  Calendars duplicate events but worse is that only contacts from Address book from letter T onwards sync.  Any contacts on iPhone which are not on Mac are lost during sync.
    Solutions?

    No, I never really found an easy solution.  I believe it is an issue with some corruption in the iTunes database on the specific device.  In my case, both my iPad and iPhone now show duplicate stream songs if viewed through iTunes on my Mac, but they show different songs.  A couple years ago I had a similar issue on my iPhone, and Apple support suggested I back up the phone, completely reset it, and then restore it from the backup.  It did work, so I imagine it would probably work for my current issues with the iPhone and iPad.  But resetting and restoring an iPad or iPhone always makes me a little nervous that something will get lost.  When I did reset/restore the iPhone, I do have to say, the restore process was 100% perfect and I did not lose any data at all even though Apple support said I might.  If you try to go that route, I would suggest backing the device up both to a computer through iTunes, and to the iCloud so that you have a double backup.
    None of this really resolves the issue with how the iTunes databases are becoming corrupted on the apple devices though, so it is very likely to happen again until they fix it.  I have been unable to determine if there were any specific actions or conditions which caused the corruption to happen in the first place.
    Might be worth another call to Apple support, or dropping in the local Apple store if you have one near by.

  • After updating to firefox 5 all my bookmarks are lost, and I can not find an old places.sqlite file. What happened to my bookmarks?

    I updated from Firefox 3 to Firefox 5 (Windows XP), and all my bookmarks are lost. Maybe I should have thought of making a backup but I did not think of this and previously after an update I could find them again. Now I can not find my bookmarks anywhere, all files in my profile have a date and time from the new installation. Is there any chance of finding my bookmarks somewhere else on my computer? If so, where are they and how can I restore them?

    Thanks for the answer. I read the article but it seems that the solution to my problem is not in there. Apart from the lost bookmarks Firefox is working fine, also I can make new bookmarks and delete them without problems. When I restart Firefox I don't loose them.
    Apparently after installing Firefox 5 everything of Firefox 3 was deleted including my profile. The only bookmark .json file I have is from the new installation, which means it does not contain any of my old bookmarks. It now has today's date and time.
    In my profile I have three 'places' files, now all with today's date and time:
    - places.sqlite (10240 kb)
    - places.sqlite-shm (32 kb)
    - places.sqlite-wal (865 kb)
    But even though places.sqlite is large, it apparently does not contain my old information. Or could it? Then how to get to it?

  • My book marks library is very unstable; they become scrambed, multiply and some are lost - solutiuon?

    My book marks library is very unstable; they become scrambed, multiply and some are lost - solutiuon?

    First of all backup your Firefox profile, or at the very least the profile file ''places.sqlite'' and the bookmarks backup folder.Put the files somewhere safe outside the Firefox paths, the Windows Desktop is suitable.
    * [[Back up and restore information in Firefox profiles]]
    Now try to repair the bookmarks database using this add-on
    * https://addons.mozilla.org/en-US/firefox/addon/places-maintenance/
    If that fails try to recreate the database by deleting the original file and allowing Firefox to restore it from a backup
    * see [[Can't add, change or save bookmarks - How to fix#w_create-a-new-bookmarks-file]]_create-a-new-bookmarks-file

  • Macbook pro fails to read sd card with movies recorded on it, any ideas? I can view them in the video camera so know they are there somewhere. I am now thinking I should have formatted or initialised the new card before using it.

    My macbook pro is failing to read a new sd card with movies recorded on it. Any ideas please? A previously used SD card has downloaded without problems. I have tried using a card reader as well as downloading from the video camera itself, neither works.
    I can view the latest recordings on the video camera so know they are there somewhere. I am now thinking I should have formatted or initialised the new card before using it but didn't think of that at the time. Obviously don't want to do this now as it will wipe the movies.

    Hi and Welcome to the Forums!
    From everything you've described, you've done everything possible. Hence, I recommend you seek out your warranty support.
    Good luck and let us know.
    Occam's Razor nearly always applies when troubleshooting technology issues!
    If anyone has been helpful to you, please show your appreciation by clicking the button inside of their post. Please click here and read, along with the threads to which it links, for helpful information to guide you as you proceed. I always recommend that you treat your BlackBerry like any other computing device, including using a regular backup schedule...click here for an article with instructions.
    Join our BBM Channels
    BSCF General Channel
    PIN: C0001B7B4   Display/Scan Bar Code
    Knowledge Base Updates
    PIN: C0005A9AA   Display/Scan Bar Code

  • I installed itunes 11. It takes 100% of cpu and GUI is not responsive for minutes at a time.  Keystrokes are lost in the search box because of this. This worked fine in previous release. I have 4300 albums and 70k  songs.

    I have an itunes library of 4000+ albums and 70k+ songs. Worked great until itunes 11 today. Now, when ever I go to the search field and type 1 character, I go to 100% CPU busy and all the other characters are lost. "itunes not responding" for a couple of minutes.  
    Also happens when I am importing a CD from physical media, and I switch to music and try and find another album. Gui becomes unresponsive and activity monitor ends up reporting "Itunes (not responding)".
    How go I go back to the working itunes?

    Thanks. That was it I don't know why it got changed during the upgrade to iTunes 11.
    However, it still takes 5-10 seconds for this menu to appear, with the cpu at 100% one core. Seems like iTunes should support multi-threaded/multi-core processing, especially for the GUI.

  • Acrobat 9 Pro: Links to Word TOC and cross references are lost

    I'm testing Acrobat 9 Pro and while it successfully creates a PDF from Word 2003 with bookmarks, all my TOC and internal page reference links are lost.
    I have triple checked the conversion settings from the Adobe PDF menu option in Word, and the "Convert cross-references and table of contents to links" check box is definitely selected.
    I used the same Word document on another machine with Acrobat 6 Pro installed - and the TOC and cross ref links were created successfully. As far as I can see the Adobe PDF settings in Word 2003 on both machines are the same - the only difference is that one uses Acrobat 6 Pro and the other uses Acrobat 9 Pro.
    The only setting in 9 Pro I turned off was the 'enable accessibility tagging' one; it's also turned off in 6 Pro. The remaining settings are the default.
    A clickable TOC and internal links is essential for my clients who often have 400+ page documents.
    Anybody have any suggestions? Or can anybody confirm that they do/don't get the same behavior in Acrobat 9 Pro?

    Thanks Abhigyan - your test PDF worked fine for me.
    This is what I've done today:
    1. Checked for all instances of pdfm*.dot files and removed any that were lurking in old Application Data and Microsoft Office folders.
    2. Deleted all Acrobat 5 and 6 folders and subfolders still lurking in Program Files.
    3. Used Add/Remove to delete Adobe Reader 8 and its updates. I figure I can always install Reader 9 if I need it as a separate app.
    4. Checked that everything was gone using the Windows Installer CleanUp utility (it was).
    5. Restarted my machine.
    6. Turned off my anti-virus software.
    7. Did a search for any pdfm*.dot files - found one only in the current Microsoft Office folder and left it there.
    8. Reinstalled Acrobat 9 Professional.
    9. Opened my test Word 2003 document.
    10. Checked all the Acrobat conversion settings and left them as the defaults.
    11. Converted the doc to PDF and checked for internal links. Yes! The TOC links worked! But my joy was short-lived as the page link didn't work...
    12. Tried various other conversion settings based on some suggestions from Lance in first level Adobe Support yesterday - still no page link. And I also lost the TOC links when I cleared the Enable Accessibility check box on the Settings tab of the conversion settings.
    13. Checked the Edit > Preferences > Convert To PDF settings for Word in Acrobat 9 - add bookmarks and add links are both selected (default).
    14. Used Acrobat 9 to create the PDF (File > Create > From File) hoping that this might might a difference. Nope. No TOC or page links.
    15. Changed conversion settings back to default via Word 2003, and created a PDF from a longer document. Again the TOC links worked, the URLs worked (they always did), the bookmarks worked (they always did too), but the none of the internal page cross-reference links worked.
    So my summary is this:
    * I can only create TOC links *if* Enable Accessibility is turned on, but I have always turned this off in earlier versions of Acrobat as I don't need it and it made the process of creating a PDF from a long document incredibly slow - I'm wary of using it!
    * I cannot get internal page links to work at all, no matter which method I use to create the PDF (from within Word or within Acrobat), and no matter which conversion settings I select.
    I really don't know what to try next. Manually creating links for what could be hundreds of cross-references in a single document is NOT an option, especially as I have many of these long documents.
    Any further suggestions?

  • Some sent mails do not appear/are not saved in "sent messages" and are lost

    i work with mail and 4 different imap accounts. about every 15th sent email "gets lost". i.e. i can follow the sending process in the activity window, and i hear the sending confirmation tone. and, usually, the mails even reach the receiver. BUT, the mails do not appear/are not saved in the "sent messages" folder and are lost. this is very unsettling, as there seems to be no recognizable pattern. can anyone help, or should i change to "entourage"? big thanks for replies
    Message was edited by: Bassolino

    Hi Bassolino and David,
    I, too, have had this intermittent issue and wonder if you had found a solution?
    In the past 3 weeks, two messages have been sent from my mac mail account, using the mail application (the only apparent common factor being that both messages had iphoto attachments), the recipients have received them - only I do not have a copy in my 'sent' folder.
    They are not stored on the macintosh server either...
    I have not altered any settings and this intermittent issue has just emerged.
    Any help from 'Top Users' would be welcome. Thanks.

  • Hello, I have changed my location and credit card for my apple id. All purchased apps I had before are lost. How can I get back my purchased apps? Thanks.

    Hello, I have changed my location and credit card for my apple id. All purchased apps I had before are lost. How can I get back my purchased apps? Thanks.

    If you are referring to an iDevice, sign out of your new Apple ID and sign back in with your old one - they should all be there.

  • I had original iPhoto app from 2007, but in the last year it stopped working seemingly out of nowhere.  Now I just installed iPhoto 9.5.1 but it won't open even after downloading the iPhoto Library Updater.  My pictures are lost in the abyss.

    I had original iPhoto app from 2007 or 2008, but in the last year it stopped working seemingly out of nowhere.  Now I just installed iPhoto 9.5.1 but it won't open even after downloading the iPhoto Library Updater.  My pictures are lost in the abyss.
    I'm using OS Extended 10.9.5.  I don't know what the original version of iPhoto was.

    I just installed iPhoto 9.5.1 but it won't open even after downloading the iPhoto Library Updater
    Have you run the iPhoto Library Upgrader? You need to direct it to the location of your old iPhoto Library by clicking the "Choose Library" button in the lower right corner of the panel you are seeing when the upgrade starts.

  • Report Alerts are not shown on crystal server 2011

    Hi,
    I have created alerts on From date and To Date. The alert is shown when the difference between From Date and To Date is more than an year. It is shown properly in the crystal report designer. When I am uploading the same report to the server the alerts are not shown on the server.
    Can someone help me with the same.
    Thanks,
    Simran

    Hi Jawahar,
    I have uploaded the report in CMC using Add--> Local Document.
    For Alerts I have checked the Box 'Enable Alert'. Still I am not getting a Pop Up which I get in the crystal report designer. Is the Alert sent on Crystal Server by email? I have currently selected default setting in Configure Alert Notification.
    Regards,
    Simran

  • After saving PDF static files, reader extended privileges (ARES) are lost

    Hi,
    Technical information:
    LiveCycle 7.0 (which came with Acrobat Professional)
    ARES 7.0
    Reader 7.0.0, 7.0.1 and 7.0.2
    Windows 2000
    PDF Static file type (as we are not dynamically adding/removing document objects)
    Scenario:
    PDF contains javascript to change the background and border colour of form fields (e.g. node.fillColor = '255,255,170' changed to '192,192,192') to denote enabled/disabled fields.
    PDFs are reader extended, so, user should be able to enter and save data on the documents multiple times.
    Problem:
    Reader extension rights of PDFs were lost. For example, in Reader, open document, update/enter data, save, and close. Do this multiple times and make sure one of the form fields background colour changes. When the document is re-opened its reader extension privileges are lost and user is no longer able to update/enter data on the document.
    This worked with our pilot forms (using AcroForm and ARES 6.0)
    ADOBE Explanation:
    The underlying XFA document is changed when the form field's background property was changed, hence, it is no longer a static form and its reader extended rights has changed.
    Resolution:
    PDF's file type changed from Static to Dynamic. Some logically driven functions will have to be changed/duplicated (e.g. calling enabling/disabling function(s) from the documents' docReady event).
    Have to use Reader 7.0.2 to be able to open, update, save, and close document multiple times without loosing reader extended rights.
    Hope this helps others
    Regards
    Jen

    Hi <br /><br />I think I am experiencing with similar issue , I am trying to do dynamic form filling using java. For this I created template wtih 4 text fields using adbobe Life Cycle designer 7.0. When I try to populate these fields through my java program, I am getting the below error<br />Exception in thread "main" java.lang.ArrayIndexOutOfBoundsException: -1        at com.cete.dynamicpdf.merger.x.a(Unknown Source)<br />        at com.cete.dynamicpdf.merger.x.<init>(Unknown Source)<br />        at com.cete.dynamicpdf.merger.PdfDocument.j(Unknown Source)<br />        at com.cete.dynamicpdf.merger.PdfDocument.<init>(Unknown rce)<br />      at com.cete.dynamicpdf.merger.PdfDocument.<init>(Unknown Source)<br />    at com.cete.dynamicpdf.merger.MergeDocument.<init>(Unknown Source)<br />        at CitiAcroFormFill.main(CitiAcroFormFill.java:26)<br /><br />I think the template had saved with Cross reference .when I use designer 7.0. How do I create and save my template as static pdf templates without having cross reference stuff?

  • Alerts are not coming in Alert Inbox SLG1

    Hi Experts,
    We have SAP NW2004s PI/XI system.
    We have defined alert configuration step by step with following,
    http://help.sap.com/saphelp_nw04s/helpdata/en/3f/81023cfa699508e10000000a11402f/frameset.htm
    /people/michal.krawczyk2/blog/2005/09/09/xi-alerts--step-by-step
    And I have checked configuration through many other threads, but don't why alerts are triggered.
    Logging Entry is checked,
    TCODE - ALRTCATDEF ->choose Settings->configuration , make sure you have the logging parameter checked.
    TCODE - SICF - AlertInbox and other services are active.
    But, I am not getting alert in Alert Inbox or SLG1 transaction.
    Error message can see through SXMB_MONI.
    When I do testing with report 'RSALERTTEST', it shows entry in both SLG1 and AlertInbox.
    Do we need to setup anything from triggering side?
    Pease help with this, it is urgent.
    Thanks,
    SamV.

    Hi Jean,
    are you looking at the SXMB_MONI on the XI system?
    Yes, It shows Mapping Error there...
    did you put your user on that alert when you configured it?alerts are asociated to specific users.
    Can you please tell me detail, I didnt get it.
    Thanks,
    SamV.

Maybe you are looking for

  • An error occurred while reading files or writing files to disc. The disc may be full or there may be

    Does anyone know why I get this error message in PSE9 on a mac computer? An error occurred while reading files or writing files to disc. The disc may be full or there may be a problem with the source media. I cant put titles on pictures or delete the

  • Manipulating Arrays

    Hi I am having trouble with 2D arrays. public class cross{ public cross() { A = new String[3][]; A[0] = new String[3]; A[1] = new String[3]; A[2] = new String[3]; for (int i = 0; i < 3; ++i) { for (int j = 0; j < 3; ++j) { A[i][j] = "Empty"; Is there

  • Query using conncet by prior

    Hi guys, We have this below table with three coloumns Id             Value                 Parentid 1234         6                                       1235         7                      1234 1239         8                      1235 1338         9 

  • Errors when trying to use time machine backup

    Here is the error I receive when trying to back up my computer with Time Machine.  Is there any way to fix it without completely wiping the Time Capsule and starting over?  My husband would love it if we could find a way since all of his back up info

  • RapidMarts - "Open file error" R3C-150607 loading from file

    Hello experts. We are installing RapidMarts for the SA-module, but when executing the main workflow in Data services we get an error trying to load the file dates.dat. The generated ABAP looks just fine, and the file exists where it should be (in SAP