Stopping Active Ip Logs - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Stopping Active IP Logs

To manually log packets on the virtual sensor for a specific IP address, follow these steps:
Log in to the CLI using an account with administrator or operator privileges.
Step 1
Start IP logging for a specific IP address:
Step 2
sensor# iplog vs0 10.16.0.0 duration 5
Logging started for virtual sensor vs0, IP address 10.16.0.0, Log ID 1
Warning: IP Logging will affect system performance.
sensor#
The example shows the sensor logging all IP packets for 5 minutes to and from the IP address 10.16.0.0.
Note
Monitor the IP log status with the iplog-status command:
Step 3
sensor# iplog-status
Log ID:
IP Address 1:
Virtual Sensor:
Status:
Event ID:
Bytes Captured:
Packets Captured:
sensor#
Note
Stopping Active IP Logs
Use the no iplog [log-id log-id | name name] command to stop logging for the logs that are in the
started
Using the no iplog command on an added state IP log stops the IP log. The added state means that the
Note
IP log is still empty (no packets). Stopping it when there are no packets means you are stopping an empty
IP log. An empty logged is removed when it is stopped.
The no iplog command does not remove or delete the IP log. It only signals to the sensor to stop
Note
capturing additional packets on that IP log.
The following options apply:
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
8-4
Make note of the Log ID for future reference.
1
10.16.0.0
vs0
added
0
0
0
Each alert references IP logs that are created because of that alert. If multiple alerts create IP
logs for the same IP address, only one IP log is created for all the alerts. Each alert references
the same IP log. However, the output of the IP log status only shows the event ID of the first alert
triggering the IP log.
state and to remove logs that are in the
log-id—Log ID of the logging session to stop. Use the iplog-status command to find the log ID.
name—Virtual sensor on which to begin or end logging.
Chapter 8
state.
added
Configuring IP Logging
78-16527-01

Advertisement

Table of Contents
loading

Table of Contents