Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual page 489

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Appendix C
Troubleshooting
Sensor Events
There are five types of events:
Events remain in the Event Store until they are overwritten by newer events.
Overview
The show events command is useful for troubleshooting event capture issues in which you are not seeing
events in Event Viewer or Security Monitor. You can use the show events command to determine which
events are being generated on the sensor to make sure events are being generated and that the fault lies
with the monitoring side.
You can clear all events from Event Store by using the clear events command.
Here are the parameters for the show events command:
sensor# show events
<cr>
alert
error
hh:mm[:ss]
log
nac
past
status
|
Displaying Events
Use the show events [{[alert [informational] [low] [medium] [high] [include-traits traits]
[exclude-traits traits]] | error [warning] [error] [fatal] | log | NAC | status}] [hh:mm:ss [month day
[year]] | past hh:mm:ss] command to display events from the Event Store.
Events are displayed beginning at the start time. If you do not specify a start time, events are displayed
beginning at the current time. If you do not specify an event type, all events are displayed.
Events are displayed as a live feed until you cancel the request by pressing Ctrl-C.
Note
The following options apply:
78-16527-01
evAlert—Intrusion detection alerts
evError—Application errors
evStatus—Status changes, such as an IP log being created
evLogTransaction—Record of control transactions processed by each sensor application
evShunRqst—Block requests
Display local system alerts.
Display error events.
Display start time.
Display log events.
Display NAC shun events.
Display events starting in the past specified time.
Display status events.
Output modifiers.
alert—Displays alerts. Provides notification of some suspicious activity that may indicate an attack
is in process or has been attempted.
If no level is selected (informational, low, medium, or high), all alert events are displayed.
include-traits—Displays alerts that have the specified traits.
exclude-traits—Does not display alerts that have the specified traits.
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
Gathering Information
C-63

Advertisement

Table of Contents
loading

Table of Contents