Why do I see no events when I perform a lookup from an access rule for which object grouping or rule optimization is enabled?
A. If object grouping or rule optimization is enabled for an access rule defined in Security Manager and the associated access-list commands on the device do not match with the optimized rules, no events are displayed in CS-MARS because of the mismatch in access rule relationship between Security Manager and the device.
Related Questions
- Is there any limit to the number of keywords that are populated in the Query page of CS-MARS when I perform events lookup from an access rule that supports hashcodes?
- Why do I see no events when I perform a lookup from an access rule for which object grouping or rule optimization is enabled?
- Can I perform events lookup from a signature that is disabled for a sensor?