ISS RealSecure IPS
We are running our ISS Proventias in prevent mode, and I have been asked to create reports that show whether an event is being blocked or not. This information is available in the SiteProtector database, but it does not appear to be pulled into enVision. Is it there, but I just do not recognize it, or has anyone else run into this issue and found a workaround (even if just editing the XML)?
I'm wondering how you made out with this issue.
We're running ISS Realsecure server sensors and I've noticed that while we are pulling events from Siteprotector - quite a bit of what we're getting are null fields.
We had the same issue when going the SNMP route, as well. I find it odd, though, since we were definitely sending the other information that we would like to see (in addition to the block counts, I am looking for detail information for reports). I think that the problem is with the device XML, and just haven't had an opportunity to play with it yet (plus, I was hoping that RSA would fix it for us and provide an update for the newest version of SiteProtector!).