Security Compliance

PortScans rule is firing excessively and sending too many email alerts in SEM

This article addresses large amounts of PortScan alerts received after a SEM upgrade or connector upgrade.

First published date

10/17/2018 9:30 PM

Last published date

10/17/2018 9:30 PM

Overview

After you upgrade Security Event Manager (formerly Log & Event Manager) or a SEM connector, you receive several PortScan alerts. 

Product section

Security Event Manager

Cause

SEM is normalizing TCP Buildup and Teardown events. Most likely, your Cisco firewall is sending TCP Buildup and Teardown events to SEM that it was not normalizing on your previous version. This can be confirmed by searching for recent TCPTrafficAudit events under nDepth and looking at the EventInfo field for Buildup and Teardown events.

Resolution

These events are numerous and not useful in most environments. The recommended solution is to change the logging level of those events so they are not sent over syslog to SEM.

See Enable SEM to Track Cisco Firewall NAT Buildup and Teardown Events for details.