To enable the local signature generation settings, use the localsig enable command in configuration mode. The no form of this command disables the signature generation.
Signatures are generated for Web Infection, Malware Object, and CnC callback alert types. Each generated signature is associated with the specified alert ID. After this command is enabled, the local signature generation component can generate the rules that are based on the alerts generated in the system. If the same malicious activity is detected within 24 hours after a signature is generated, the rule will have a signature match based on the generated local signature. The system can track the original alert that caused the signature creation. Signatures will expire in 24 hours based on the updated time and date stamp in the system. A signature can be created again if suppression is removed from an alert. A signature cannot be created again if the alert is resolved.
Syntax
[no] localsig enable
Parameters
None
Example
The following example enables the local signature generation settings.
hostname (config) # localsig enable
User role
Admin
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Central Management System: Release 7.5.0
Email Security — Server: Release 7.6.0
Network Security: Release 7.5.0