Forum Discussion
teppotahkapaa
Leader
24 days agoHi Antonio,
thanks for response.
Event Policy is "Message Collector managing devices with same secondary IP". Of course I can disable that EP totally though all those messages will be in Logs still, and there are plenty of those. And I tend to believe that there is a reason for this EP.
I know that technically per se it is not a huge issue, just lots of events, when having lots of clustered firewalls with lots for common IPs.
Now I am a bit confused about port/interface definitions in SL1.
- Interface scan = interface scan, but also IP scan? If enabling Bypass Interface Inventory, then no updates for any changes in interfaces will be done?
- port scan = TCP port scan and can be then defined if scanning for each IP or not
Well, you can delete those IPs (in mysql) but seems that they just popup again and again. So in reality it looks like there is no way to disable that feature per devices but still continue with normal interface monitoring.