localsig enable

Prev Next

To enable the local signature generation settings, use the localsig enable command in configuration mode. The no form of this command disables the signature generation.

Signatures are generated for Web Infection, Malware Object, and CnC callback alert types. Each generated signature is associated with the specified alert ID. After this command is enabled, the local signature generation component can generate the rules that are based on the alerts generated in the system. If the same malicious activity is detected within 24 hours after a signature is generated, the rule will have a signature match based on the generated local signature. The system can track the original alert that caused the signature creation. Signatures will expire in 24 hours based on the updated time and date stamp in the system. A signature can be created again if suppression is removed from an alert. A signature cannot be created again if the alert is resolved.

Syntax

[no] localsig enable

Parameters

None

Example

The following example enables the local signature generation settings.

hostname (config) # localsig enable

User role

Admin

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Central Management System: Release 7.5.0

  • Email Security — Server: Release 7.6.0

  • Network Security: Release 7.5.0