Understanding IPS log (sig:16297-Worm Activity)

Hi,
We are monitoring intrusions for a customer using SIEM and we got an alert based on the below IPS logs.
It would be great if someone helps clarify my doubts in analyzing this and similar IPS logs.
*********** Cisco IDS    08 Oct 2012 08:50:36    id= xyxyxyxyxyxyxyxyxyx    sig_id= 16297    sig= Worm Activity - Brute Force    src= 10.10.10.4    src_port= [3539]    dst= 192.168.178.131    dst_port= [445]    sev= informational    proto= tcp    eventId=1340445327004327804    severity=informational    vendor=Cisco    sd:originator.sd:hostId=AIP-SSM-1    sd:originator.cid:appName=sensorApp    sd:originator.cid:appInstanceId=462    sd:time.offset=XYZ    sd:time.timeZone=XYZ    sd:time=1349686236842887000    sd:signature.cid:created=20090331    sd:signature.cid:type=anomaly    sd:signature.cid:version=S392    sd:signature.description=Worm Activity - Brute Force    sd:signature.id=16297    sd:signature.cid:subsigId=0    sd:signature.cid:sigDetails=Multiple logon failures    sd:signature.marsCategory=Propagate/Worm    sd:interfaceGroup=vs0    sd:vlan=0    sd:participants.sd:attacker.sd:addr.cid:locality=OUT    sd:participants.sd:attacker.sd:addr=10.10.10.4   sd:participants.sd:attacker.sd:port=3539    sd:participants.sd:target.sd:addr.cid:locality=OUT    sd:participants.sd:target.sd:addr=192.168.178.131    sd:participants.sd:target.sd:port=445    sd:participants.sd:target.cid:os.idSource=learned    sd:participants.sd:target.cid:os.relevance=relevant    sd:participants.sd:target.cid:os.type=windows-nt-2k-xp    sd:participants.sd:target.cid:os=    cid:context.cid:fromTarget= <removed> cid:context.cid:fromAttacker=<removed>    cid:alertDetails=InterfaceAttributes:  context="single_vf" physical="Unknown" backplane="GigabitEthernet0/1" ;     cid:triggerPacket=<removed>  cid:riskRatingValue.attackRelevanceRating=relevant    cid:riskRatingValue.targetValueRating=medium    cid:riskRatingValue=25    cid:threatRatingValue=25    cid:interface.backplane=GigabitEthernet0/1    cid:interface.context=single_vf    cid:interface.physical=Unknown    cid:interface=GigabitEthernet0/1    cid:protocol=tcp ************
1. I checked for sig:16297 via ASDM demo version, but didn't found this signature in sig0. Where can we see this signature settings and properties.
2. The fields "cid:context.cid:fromTarget=", "cid:context.cid:fromAttacker=", & "cid:triggerPacket=" looks to be like encoded format. How to decode this, any tools/URL? How these fields are significant
3. If this is false postivie (based on src/dst and activity), how to fine tune this in IPS?
Note: I don't have access to this IPS. But, I need to coach the owner for fine tuning and for other checks.
Thanks!
-Jag.

Hi Jag.
Here is a link with more information on alert 16297/0. 
tools.cisco.com/security/center/viewIpsSignature.x?signatureId=16297&signatureSubId=1&softwareVersion=6.0&releaseVersion=S392
Generally on that signature I'd email the customer and ask them to check the attacker IP to ensure that the computer doesn't have a virus.  If these end up coming in frequently and the customer comes back stating they are false alerts then you may need to filter the alert or just send a report to the customer once a week with the IPs in question from the alert.
As far as decoding the fields in question 2, that comes out in base64.  We have a powershell script that decodes these fields.  I have tried various Web based decoders with mixed success which is why we wrote a powershell script to do the job.

Similar Messages

  • Decoding IPS logs

    Hi,
    Need guidance on decoding IPS syslogs(alerts). We monitor IPS logs and there we could see some decoded messages appearing for cid.context.cid:fromTarget, cid.context.cid.fromAttacket, cid.triggerPacket fields. Would like to understand what these fields are, how to decode these messages (any tools/url for decoding), why cisco has made these contents to appear decoded (any specific reason), how this will help us in analyzing such alerts.
    Thanks!
    -Jag.

    Please use the below guide for message fields
    http://www.cisco.com/c/en/us/td/docs/security/ips/7-0/configuration/guide/cli/cliguide7/cli_packets.html

  • How to logging off the assign activity to dehydration store

    As per my understanding , every bpel process, logs data from assign activity in dehydration store. I changed the setting auditLevel to production to for logging off the assign activity.
    But it didnt work I guess. Even I tried to query audit_details & audit_trail tables by instance id.
    But didnt get the record that I got. Can we get variables stored ?
    Please help me in logging off assign activity to dehydration store which is default behaviour. And also how to cross check it.
    Thanks in advance.

    Look here:
    http://download.oracle.com/docs/cd/B31017_01/core.1013/b28942/tuning_bpel.htm#CIHEFIFH
    Use the
    "completionPersistPolicy BPEL Property"
    "inMemoryOptimization BPEL Property"
    In your BPEL process.
    Marc

  • Understanding http log

    Hi,
    I know that the doc did specify a very high level of understanding the log:
    dateTime hostName processName[pid]: category logLevel: eventMessage
    However I have couple of questions here:
    Q1) Why is there different IP addresses shown? 129.2.20.19 is the load balancer and 136.14.130.21 is from PC.
    Q2) What is the difference between the 2 time stamps, one at the beginning and one at the end of each entry?
    Example: ..03/Jun/2005:14:58:00....14:56:57 0:01:03.....
    [03/Jun/2005:14:58:00 +0800] mux1 httpd[10763]: Account Notice: close [129.2.20.19] [unauthenticated] 2005/6/3 14:58:00 0:00:00 19 149 0
    [03/Jun/2005:14:58:00 +0800] mux1 httpd[10763]: Account Notice: close [192.168.48.109] [unauthenticated] 2005/6/3 14:58:00 0:00:00 623 262 0
    [03/Jun/2005:14:58:00 +0800] mux1 httpd[10763]: Account Notice: close [136.14.130.21] [unauthenticated] 2005/6/3 14:56:57 0:01:03 1330 604 0
    [03/Jun/2005:14:58:00 +0800] mux1 httpd[10763]: Account Notice: close [136.14.130.21] [unauthenticated] 2005/6/3 14:56:56 0:01:04 2435 3698 0

    Hi,
    I know that the doc did specify a very high level of
    understanding the log:
    dateTime hostName processName[pid]: category
    logLevel: eventMessage
    However I have couple of questions here:
    Q1) Why is there different IP addresses shown?
    129.2.20.19 is the load balancer and 136.14.130.21
    1 is from PC.The ip is the address of the system that connected. It's reporting that. If one of your users connected directly, then his ip is reported. We must know the ip where the connection is happening, if we're going to have ip security.
    Q2) What is the difference between the 2 time stamps,
    one at the beginning and one at the end of each
    entry?Login time vs log out time? I'm not exactly sure, myself.
    Why is this important to you? The timestamp on the left is the logout time.
    >
    Example: ..03/Jun/2005:14:58:00....14:56:57
    0:01:03.....
    [03/Jun/2005:14:58:00 +0800] mux1 httpd[10763]:
    Account Notice: close [129.2.20.19] [unauthenticated]
    2005/6/3 14:58:00 0:00:00 19 149 0
    [03/Jun/2005:14:58:00 +0800] mux1 httpd[10763]:
    Account Notice: close [192.168.48.109]
    [unauthenticated] 2005/6/3 14:58:00 0:00:00 623 262
    0
    [03/Jun/2005:14:58:00 +0800] mux1 httpd[10763]:
    Account Notice: close [136.14.130.21]
    [unauthenticated] 2005/6/3 14:56:57 0:01:03 1330 604
    0
    [03/Jun/2005:14:58:00 +0800] mux1 httpd[10763]:
    Account Notice: close [136.14.130.21]
    [unauthenticated] 2005/6/3 14:56:56 0:01:04 2435 3698
    0

  • Digital Editions: The account you tried to log in with is activated on too many devices.

    Digital Editions: The account you tried to log in with is activated on too many devices.
    How do i reset it???
    Chat does not run, my english is not got enough to call the hotline.
    I didn*t find out how to contact adobe support by email :-(((
    So, what can i do?  Please help.
    Otherwise, i can not read my ebooks any longer :-(((

    The only people that I'm aware of who can reset your activation count is
    the Adobe Help line that you call.  And many of those people have to be
    told that it is their job.  This forum does not have the ability to forward
    posts to Adobe technical support to get these kinds of problems resolved.
    Trust in your English - or perhaps have a friend that speaks English better
    do the talking.
    I have to ask what you have been doing that used up all of the
    activations.  We need to fix the root of the problem.
    =================

  • Urjent:Partition error:Logging out user [Admin], active for 0 minutes

    Hi all,
    Iam using 11
    Wen iam creating Transaparent partition its validating successfully , but wen iam saving it its giving error , partition creation failed
    Error: 1051037: Logging out user [Admin], active for 0 minutes
    and it s giving error reading ddb file
    i tried with maxl also but it continiously running for 30 mints , its horrible , actually it takes 2 mints
    how can i resolve this issue, any help would be appriciated
    thanks
    Edited by: user8815661 on 26 avr. 2010 05:18
    Edited by: user8815661 on 27 avr. 2010 04:00
    Edited by: user8815661 on 3 mai 2010 04:18

    Sounds like there is some sort of ddb file corruption. There are many causes, but the quickest fix I have found is usually a file-based deletion of the ddb file on both the source and target side of this partition. The attempt to create a partition on this database will cause a new ddb file to be created. Of course, this is dangerous. You can't have any other partitions on either the source or target side...or they will be deleted by this step. But the only purpose of the ddb file is for partition definitions, and it exists on both source and target.
    I've found this happens if one side of a partition (one of the ddbs from source or target) gets the file deleted, or communication is down between the source database server and target database server.

  • IPS log and monitoring

    Hi, All
    Few Queries on Cisco IPS.!!!!
    1. Which are best tool for fetching cisco IPS logs??
    2. Where or Which directory Cisco Logs/Events are saved?
    3. I am only able to see today log but not able to view past any logs? what are possible cause?
    4. Any free-ware tool that fetch logs and events from cisco IPS?
    5. Cisco IPS express manager is free-ware or we need only cisco customer account?
    For any type of help.. Thanks
    Jignesh

    1. You can use IME (IPS Manager Express) to view all your IPS events.
    Here is the IME page for your reference:
    http://www.cisco.com/en/US/products/ps9610/index.html
    2. The logs on the IPS device itself has very small storage space and it wraps once the log is full, therefore if you have a lot of events triggered, you are only able to see the latest events.
    3. As per my above description.
    4. Cisco IME - it's free (no extra license is required to use IME).
    5. As long as you have CCO account, you should be able to download the IME software.
    Hope this helps.

  • IPS Log store on some other location

    Hi,
    we have following 4 ASA with IPS module.
    1. Cisco ASA 5510 with IPS
    2. Cisco ASA 5520 with IPS
    3. Cisco ASA 5515X with IPS
    4. Cisco ASA 5525x with SSD with IPS
    I am checking IPS log on IPS individually login . I need store/save this log on some other location.
    Please help us, how can I do.
    Regards
    Vinod Gupta
    9810966625

    Yes.  Buy it and sign on with your other Macs using the same AppleID.  It will be available in the Purchases tab.
    You can also make a copy of it after the first download and move it to your other machines to avoid another 4 gig download.   Make sure to do this before installing as the installer will delete the download from the applications folder.

  • IPS 4240 Sig Update License

    Is this the correct part no. for the IPS 4240 Sig Update License?  CON-SUSA-IPS4240S
    I can only find this part number in the ordering tool: CON-SUI-IPS4240 which also has SMARTNet Support?
    Which one do we need just for having Sig Updates?
    Thanks

    You can't purchase a standalone IPS subscription for IPS appliance.
    You have to purchase either of the following:
    1) CON-SUI-IPS4240 for example that includes Smartnet for hardware, software as well as the IPS subscription.
    OR/
    2) CON-SUSA-IPS4240 contracts are only sold to customer who have purchased a hardware and software support contract through a reseller/partner.
    CON-SUSA... can't be sold on its own, it must be sold in conjunction with the reseller/partner support contract.
    Hope that helps.

  • Log on ticket not activated on the server

    Hi all
    When i tried to test compont crm_ui_frame,using transaction code bsp_wd_cmpwd,it opens  the url
    Where in, i am not able to enter user name and password, those fields are gray out. System seeking the fallowing errors:
    1) .  sso log on not passable, log on ticket not activated on the server.
    2).No switch to https occurred so it is not secure to send a password. for which i try to activated the profiles using transaction code:RZ10. the fallowing profiles are
    Login/accept_sso2_ticket=1, login/create_sso2_ticket=2. While doing this i  am getting errors, so i could not able to activate those profiles. The following errors are
    E: login/accept_sso2_ticket not a logical value 1#.
    W: unknown parameter. Start up/ trimming_propertics, a check cannot be performed.
    W: unknown parameter. Start up/um/home, a check cannot be performed.
    W: unknown parameter .start up / max_coches, a check cannot be performed.
    E: jstart up/ instance_propertics file D:\usr\sap\c27\DVEBMGS00\J2EE\cluster\ instance.
    E: Exe\j2ee.file D:\usr\sap\c27\DVEBMGS00\exe\ jcontrol.exe .does not exist.
    Hence, please help me in this regards, and for your kind information, i have crm2007 and TREX servers both are on single machine, and i do have DNS server connected to my system.
    Regards
    padmarao.

    Hi,
    >E: login/accept_sso2_ticket not a logical value 1#.
    Check if the value is really "1" and not "1#".
    I have these parameters set on my CRM 2007 system and the saplpgon ticket works fine.
    >2).No switch to https occurred so it is not secure to send a password. f
    You have to activate HTTPS for the ICM and you have to choose "Logon via HTTPS" for the
    /sap/crm_logon service in SICF.
    Regards,
    Olivier

  • Understanding Server Log

    I am really grateful to members of this forum in helping and guiding me in setting up my first server. Everything appears to be running smoothly so far.  The monitoring strategy and understanding the server log will be critical. Can anyone point me to documentation that would help understanding the server log?

    Nope.  Sorry.
    There is no general documentation of the server logs (beyond scattered postings and web pages, and the associated source code for various associated component tools as that code is available, and details of logs and errors for some of the specific components from their respective maintainers), nor would I expect this sort of general console log documentation to be available due to the sheer breadth of componentry and the churn from the OS X updates and upgrades.  The process of learning the logs involves watching and learning what's normal operation for a specific server, and what sorts of patterns — blocks of repeated errors, daemons crashing and restarting, unusual delays or such — that indicate issues.   Some of the normal log chatter can look quite draconian and can spook readers, with the ClamAV warning being a popular example of this, as are various (paraphrasing) OMG OUTDATED API warnings for OS X components.
    If you're starting to deal with a number of systems, then you'll be looking at implementing log analysis tools and rules, SNMP and syslog to manage the chatter.
    As a more general discussion, learning the individual components from available resources is entirely reasonable and recommended, as might be learning the structure of the OS X kernel and maybe then looking at application crashes and such for more advanced understanding.  There are books and videos and various web pages on the components.  Once you know how the pieces work, knowing what's normal in the logs is a little easier.
    Monitoring system activity can help, too.  It's fairly common to see a failure generate excessive disk I/O or processor activity, and spool up the fans.  Security breaches and DDoSes and such can generate similar loads.  The server gets, well, hot.  If you watch the server and network activity, you can know when your system is busy, and know when it's busy for no obvious or good reason.  At a more advanced policy and planning level, plotting activity over time can tell you when your server is headed toward an overload.
    Monitoring the core server forum postings via RSS feeds (eg: this forum) can help spot trends and what become known bugs, as can be membership on the Mac Enterprise mailing list.  I also follow various security-oriented notification lists and RSS feeds, including those RSS feeds from Apple and those associated with components and tools I use.  (These can also help you learn the system and the tools, too.)
    More generally, have backups, consider and potentially implement periodic off-site backups, learn IP networking and DNS and maybe managed switches and DMZs and the rest if and as you scale up, get onto notification lists for the tools and products that you use (particularly for security reports), and (generally) don't rush to upgrade OS X Server save for cases involving actively-exploited or critical security or stability problems — have your reasons for upgrading and consider the trade-offs against not upgrading, and "shiny" isn't usually one of the best reasons for an upgrade.

  • Cisco ips logging options (SDEE, IME, Archiving)

    Based on the following post, cisco IPS' can send basic syslog messages: https://supportforums.cisco.com/discussion/12180461/cisco-asa-5585-syslog-options-ips
    Does anyone know which messages are sent via syslog?
    Also, I understand the Cisco IME can be used to retrieve SDEE logs. I understand it can archive files. I need to make sure the logs are archived, and kept for at least a year. My concern for Cisco IME is that I won't know if the IME application fails or not. I believe it needs to be running in order for it to retrieve the SDEE logs.
    Also, if the max number of archived files ever hits, is it possible to move old files to another folder? And then move those files back when they need to be viewed in the IME?
    I am also hitting a deadend when it comes to finding alternatives for logging SDEE events. Splunk used to have a tool that could do this. But it is now deprecated. Anyone aware of any good SDEE retrival tools?
    Any suggestions are appreciated

    There are very few IPS-related syslog messages generated -  primarily health of the overall sensor device or platform. Anything useful as far as actual IPS intrusion events, attempts etc. will only be available on the legacy Cisco IPS platforms via SDEE.
    Cisco IME (free, limited number of managed devices, runs on a PC without any real archiving etc.) is the least cost option to retrieve and display the events.
    Stepping up in the Cisco offerings would be to use Cisco Security Manager. It does archiving, hierarchical storage etc. However it's days are numbered as Cisco revamps both  the IPS and traditional ASA features to account for both their development of CX-related products (including IPS) and the SourceFire product line. I don't now that I'd recommend CSM for a new buy.
    If you have existing Cisco IPS and really need to archive the SDEE-retrieved events, then you could use LogRhythm or such as noted in the earlier reply.

  • Cannot log into DTR with Active Directory User

    Greetings,
    I have set up and installed JDI correctly.  I can log into /devinf, the cbs, cms and sld systems with no problem using both Administrator and my JDI.Administrator that I assigned to an Active Directory user.  I can log into the DTR using a user from the database (i.e. Administrator), however, when trying to access the DTR with an Active Directory user, I get the following message:
    500   Internal Server Error
      SAP J2EE Engine/6.40 
      Application error occurred during the request procession.
      Details:   Error [javax.servlet.ServletException: Group found, but unique name "businessUnit.all.guests" is not unique!], with root cause [com.tssap.dtr.server.deltav.InternalServerException: Group found, but unique name "businessUnit.all.guests" is not unique!].  The ID of this error is
    Exception id: [0012798F81680042000000090000165C0003FE9AA3C0B86B].
    This group exists in multiple domainshowever, this has not caused us any issues to date with our portal and other pieces of SAP WASit's only this DTR error. 
    Any help is greatly appreciated.
    Thanks,
    Marty

    Hi Marty,
    In the document available at the link enclosed below, there is a part that explains how to configure DTR so that it always uses "Unique-IDs".
    http://help.sap.com/saphelp_nw04/helpdata/en/20/f4a94076b63713e10000000a155106/frameset.htm
    It is mentioned that this is valid for LDAP, but the information is applicable for Active Directory as well.
    Regards,
    Manohar

  • Issue understanding PFRO Log

    Hey Everyone,
    I have, what I hope to be a pretty simple question.  Here we go.
    I was looking at the PFRO Logs as I am trying to understand different system level things, for a class I am taking on System Administration (I am taking a deeper dive).  When I came across the PFRO logs, I found something similar to the following:
    7/22/2011 10:43:23 - PFRO Error: \??\C:\Users\UserName\AppData\Local\Temp\download_file_name.exe, |delete operation|, 0xc000003a
    7/22/2011 10:43:23 - 1 Successful PFRO operations
    Does this mean that the system was deleting the file "download_file_name.exe" and it was successful.  As this is what it appears to be.  I am not sure, and hoping someone can clarify as the "PFRO Error" is throwing me off.
    Any help is greatly appreciated.
    Thanks in advance.
    Darksider

    Hi,
    Some products and updates use a registry key to store information about pending file rename operations (PFRO). This feature is used when files that have to be updated that are locked or that are being used, the installer writes the files to a temp location
    and renames them after a restart.
    The delete operation in your log means that the file (the pending file) is successfully deleted after a restart.
    Kate Li
    TechNet Community Support

  • Understanding MapViewer log - total time loading X features

    Hi All,
    I'm interested in finding out more about how to understand the following lines from the log file.
    What I'm unsure about is what "total time loading features" means. For example Theme_14 has a sql exec time of 1797ms, however the total time loading 3 features is 21233ms.
    I'm assuming the total time includes the sql exec time. However there is about 20 seconds extra. Understanding this time should allow me to make changes to reduce it.
    What is MapViewer doing in that time? / What are the components that make up the "total time loading features"?
    Mon Apr 21 14:57:30 EST 2008 DEBUG [oracle.sdovis.theme.pgtp] [ THEME_1 ] sql exec time: 63ms, total time loading 0 features: 63ms.
    Mon Apr 21 14:57:30 EST 2008 DEBUG [oracle.sdovis.theme.pgtp] [ THEME_2 ] sql exec time: 422ms, total time loading 0 features: 422ms.
    Mon Apr 21 14:57:30 EST 2008 DEBUG [oracle.sdovis.theme.pgtp] [ THEME_3 ] sql exec time: 422ms, total time loading 7 features: 422ms.
    Mon Apr 21 14:57:30 EST 2008 DEBUG [oracle.sdovis.theme.pgtp] [ THEME_4 ] sql exec time: 422ms, total time loading 0 features: 422ms.
    Mon Apr 21 14:57:30 EST 2008 DEBUG [oracle.sdovis.theme.pgtp] [ THEME_5 ] sql exec time: 516ms, total time loading 0 features: 516ms.
    Mon Apr 21 14:57:30 EST 2008 DEBUG [oracle.sdovis.theme.pgtp] [ THEME_6 ] sql exec time: 500ms, total time loading 0 features: 500ms.
    Mon Apr 21 14:57:30 EST 2008 DEBUG [oracle.sdovis.theme.pgtp] [ THEME_7 ] sql exec time: 516ms, total time loading 0 features: 516ms.
    Mon Apr 21 14:57:30 EST 2008 DEBUG [oracle.sdovis.theme.pgtp] [ THEME_8 ] sql exec time: 422ms, total time loading 5 features: 422ms.
    Mon Apr 21 14:57:30 EST 2008 DEBUG [oracle.sdovis.theme.pgtp] [ THEME_9 ] sql exec time: 516ms, total time loading 0 features: 516ms.
    Mon Apr 21 14:57:31 EST 2008 DEBUG [oracle.sdovis.theme.pgtp] [ THEME_10 ] sql exec time: 218ms, total time loading 0 features: 218ms.
    Mon Apr 21 14:57:31 EST 2008 DEBUG [oracle.sdovis.theme.pgtp] [ THEME_11 ] sql exec time: 437ms, total time loading 12 features: 453ms.
    Mon Apr 21 14:57:31 EST 2008 DEBUG [oracle.sdovis.theme.pgtp] [ THEME_12 ] sql exec time: 766ms, total time loading 16 features: 1141ms.
    Mon Apr 21 14:57:32 EST 2008 DEBUG [oracle.sdovis.theme.pgtp] [ THEME_13 ] sql exec time: 906ms, total time loading 1 features: 1735ms.
    Mon Apr 21 14:57:51 EST 2008 DEBUG [oracle.sdovis.theme.pgtp] [ THEME_14 ] sql exec time: 1797ms, total time loading 3 features: 21233ms.
    Mon Apr 21 14:57:51 EST 2008 INFO [oracle.sdovis.DBMapMaker] **** time spent on loading features: 21233ms.
    Your time is appreciated. Any other comments are also welcome.

    Hi,
    the "total time loading features" includes the whole process to prepare the theme data. It includes the SQL execution time plus the data fetching plus some other minor tasks which do not affect much the final total time. So basically look for the SQL exec time and the fetching/loading of data. In your case, the fetching/loading of THEME_14 geometries is taking too long. Also the SQL exec time for just 3 features seems high. For the fetching, check if the geometries are too detailed (too may points), and for the SQL check if you can improve it (the log, in finest mode, also shows the query executed).
    Joao

Maybe you are looking for

  • ASA multiple mode upgrade from 8.2.5 to 8.4.5 to 9.0.3

    I'm doing ASA  code upgrade with contexts  from 8.2.5 to 8.4.5 to 9.0.3 and I'm concerned about the NAT syntax with the new code. Should this automatically changed to the new syntax on all contexts or I have to do it manually. Anyone there with that

  • New Iphone 4s price with ATNT contract

    If I lost my Iphone what should I do? and what price would get a new one if I have Atnt contract? get a new one as I have ATNT contract

  • Price list type at item in CRMD_ORDER

    Hi, I need to change the price list at item level in CRMD_ORDER. Can you please help me in finding out the right BADI. I have used  BADI "crm_cond_badi" which is at item level but the header price list ( coming from customer master data) is overwritt

  • Weblogic 10.3.6 and OSM 7.0.3 p13 managed server

    Hi, Just a very high level question. I've been searching for application compatibility between weblogic and OSM. We are currently running an weblogic 10.3.1 with an OSM 7.0.3 patch 6 managed server. We are looking at upgrading to weblogic to 10.3.6 a

  • Firefighter Log in Error

    Hi Experts... I have configured a FFUserid, assigned to a firefighter and the Owner and the Controller. When the Firefighter try to log on, a message of "The FFUser Does not exist. message /VIRSA/VFAT621. Could anybody help me, please?