Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual page 490

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Gathering Information
traits—Trait bit position in decimal (0 to 15).
error—Displays error events. Error events are generated by services when error conditions are
encountered.
log—Displays log events. Log events are generated when a transaction is received and responded to
by an application. Contains information about the request, response, and success or failure of the
transaction.
NAC—Displays Network Access Controller (block) requests.
status—Displays status events.
past—Displays events starting in the past for the specified hours, minutes, and seconds.
hh:mm:ss—Hours, minutes, and seconds in the past to begin the display.
The show events command waits until a specified event is available. It continues to wait and display
Note
events until you exit by pressing Ctrl-C.
To display events from the Event Store, follow these steps:
Log in to the CLI.
Step 1
Display all events starting now:
Step 2
sensor#@ show events
evError: eventId=1041472274774840147 severity=warning vendor=Cisco
originator:
hostId: sensor2
appName: cidwebserver
appInstanceId: 12075
time: 2003/01/07 04:41:45 2003/01/07 04:41:45 UTC
errorMessage: name=errWarning received fatal alert: certificate_unknown
evError: eventId=1041472274774840148 severity=error vendor=Cisco
originator:
hostId: sensor2
appName: cidwebserver
appInstanceId: 351
time: 2003/01/07 04:41:45 2003/01/07 04:41:45 UTC
errorMessage: name=errTransport WebSession::sessionTask(6) TLS connection exce
ption: handshake incomplete.
The feed continues showing all events until you press Ctrl-C.
Step 3
Display the block requests beginning at 10:00 a.m. on February 9, 2005:
sensor#@ show events NAC 10:00:00 Feb 9 2005
evShunRqst: eventId=1106837332219222281 vendor=Cisco
originator:
deviceName: Sensor1
appName: NetworkAccessControllerApp
appInstance: 654
time: 2005/02/09 10:33:31 2004/08/09 13:13:31
shunInfo:
host: connectionShun=false
timeoutMinutes: 40
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
C-64
srcAddr: 11.0.0.1
destAddr:
srcPort:
destPort:
protocol: numericType=0 other
Appendix C
Troubleshooting
78-16527-01

Advertisement

Table of Contents
loading

Table of Contents