Cisco Bug: CSCtb92648 - Custom column query with keyword doesn't return results
Sep 11, 2015
- Cisco Security Monitoring, Analysis and Response System
Known Affected Releases
Symptom: When performing a query that returns the raw message of an event retrieved from a Cisco IPS sensor, the raw message will not have the "Actions" data present. (action data for IPS events indicate the actions that were performed by the signature when it fired. e.g. "deniedFlow", "deniedAttacker", "blockConnectionRequested", "droppedPacket", "deniedPacket", "deniedConnection", "tcpOneWayResetSent", etc.) Conditions: MARS 6.0.x retrieving events from Cisco IPS 6.x or 7.x sensors. Only queries run against events already received are subject to this defect. Scheduled reports should be unaffected.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.
Bug Details Include
- Full Description (including symptoms, conditions and workarounds)
- Known Fixed Releases
- Related Community Discussions
- Number of Related Support Cases