AnsweredAssumed Answered

Identifying Msg_IDs description in ESA Alerts

Question asked by Wardell Motley on Jun 14, 2016
Latest reply on Sep 25, 2016 by Sal Sanshez

Hi everyone!

 

We are currently working on some tuning in ESA alerts and came across some MSG_ids  that we cannot identify

The two alerts are listed below with associated message IDs that we need descriptions for

 

- Multiple Logs from MsgID Set with Same SourceIP DestinationIP

Msg_id in the syntax of the rule are ('00490' , ' 00490:08',' 00490:21' , '00004:16', ' 00490:01', '00490:07' , '00490:08' , '106001','106001:01','106002'

 

 

-Multiple Unique Logs from MsgID Set with Same Source and Destination IP

Msg_id in the syntax of the rule are ('00490', '00490:06','00490:08','00490:21')

Outcomes