Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual page 231

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Chapter 13
Administrative Tasks for the Sensor
To display events from the Event Store, follow these steps:
Log in to the CLI.
Step 1
Display all events starting now:
Step 2
sensor#@ show events
evError: eventId=1041472274774840147 severity=warning vendor=Cisco
originator:
hostId: sensor2
appName: cidwebserver
appInstanceId: 12075
time: 2003/01/07 04:41:45 2003/01/07 04:41:45 UTC
errorMessage: name=errWarning received fatal alert: certificate_unknown
evError: eventId=1041472274774840148 severity=error vendor=Cisco
originator:
hostId: sensor2
appName: cidwebserver
appInstanceId: 351
time: 2003/01/07 04:41:45 2003/01/07 04:41:45 UTC
errorMessage: name=errTransport WebSession::sessionTask(6) TLS connection exce
ption: handshake incomplete.
The feed continues showing all events until you press Ctrl-C.
Display the block requests beginning at 10:00 a.m. on February 9, 2005:
Step 3
sensor#@ show events NAC 10:00:00 Feb 9 2005
evShunRqst: eventId=1106837332219222281 vendor=Cisco
originator:
deviceName: Sensor1
appName: NetworkAccessControllerApp
appInstance: 654
time: 2005/02/09 10:33:31 2004/08/09 13:13:31
shunInfo:
host: connectionShun=false
timeoutMinutes: 40
evAlertRef: hostId=esendHost 123456789012345678
sensor#
Display errors with the warning level starting at 10:00 a.m. February 9 2005:
Step 4
sensor# show events error warning 10:00:00 Feb 9 2005
evError: eventId=1041472274774840197 severity=warning vendor=Cisco
originator:
hostId: sensor
appName: cidwebserver
appInstanceId: 12160
time: 2003/01/07 04:49:25 2003/01/07 04:49:25 UTC
errorMessage: name=errWarning received fatal alert: certificate_unknown
Display alerts from the past 45 seconds:
Step 5
sensor# show events alert past 00:00:45
evIdsAlert: eventId=1109695939102805307 severity=medium vendor=Cisco
originator:
hostId: sensor
78-16527-01
srcAddr: 11.0.0.1
destAddr:
srcPort:
destPort:
protocol: numericType=0 other
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
Events
13-5

Advertisement

Table of Contents
loading

Table of Contents