If Cisco IPS is showing 0.0.0.0 as victim or attacker ip what does it mean?

IPS summarisation is a process which enables the user to aggregate multiple events in a single alert. It is done because it reduces the number of alerts sent to the administrator. Anytime user see the 0.0.0.0 address used in the victim or attacker IP address field it is the result of multiple victim IP addresses being summarized. User may see signatures that will tell you the first 10 or so IP addresses that were summarized by looking at the detailed event.