signatureid
idrule
ipproto
srcip
srcport
destip
destport
internalid
Context Parameters Rule Name
Deep Inspection
2.24.3. intrusion_detected (ID: 01300003)
Default Severity WARNING
Log Message Intrusion detected: <description>, Signature ID=<signatureid>. ID
Rule: <idrule>. Protocol: <ipproto>. Source IP: <srcip>. Source Port:
<srcport>. Destination IP: <destip>. Destination Port: <destport>.
Internal ID: <internalid>. Closing connection.
Explanation An attack signature mapped to the "protect" action matched the
traffic.
Gateway Action close
Recommended Action Research the advisory (searchable by the unique ID).
Revision 2
Parameters description
signatureid
idrule
ipproto
srcip
srcport
destip
destport
internalid
Context Parameters Rule Name
Deep Inspection
2.24.4. virus_detected (ID: 01300004)
Default Severity WARNING
Log Message Virus/worm detected: <description>, Signature ID=<signatureid>.
ID Rule: <idrule>. Protocol: <ipproto>. Source IP: <srcip>. Source
Port: <srcport>. Destination IP: <destip>. Destination Port:
<destport>. Internal ID: <internalid>. Closing connection.
Explanation A virus signature mapped to the "protect" action matched the traffic.
Gateway Action close
Chapter 2: Log Message Reference
291