Unable To See Alerts - Cisco IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor Installation And Configuration Manual

Intrusion detection system appliance and module
Table of Contents

Advertisement

Troubleshooting the 4200 Series Appliance

Unable to See Alerts

Step 1
Step 2
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
B-14
If you cannot see alerts, the following:
Make sure the signature is enabled.
Make sure the sensor is seeing packets.
Make sure that alerts are being generated.
Make sure Event Viewer can communicate with the sensor.
To make sure you can see alerts, follow these steps:
Log in to the CLI.
Make sure the signature is enabled:
Enter configuration mode:
a.
sensor# configure terminal
b.
Enter virtual sensor mode:
sensor(config)# service virtual-sensor-configuration virtualSensor
Make sure the signature is enabled:
c.
sensor(config-vsc)# tune-micro-engines
sensor(config-vsc-virtualSensor# atomic.icmp
sensor(config-vsc-virtualSensor-ATO)# sig sigid 2000
sensor(config-vsc-virtualSensor-ATO-sig)# show settings
SIGID: 2000 <protected>
SubSig: 0 <protected>
AlarmDelayTimer:
AlarmInterval:
AlarmSeverity: informational <defaulted>
AlarmThrottle: Summarize <defaulted>
AlarmTraits:
CapturePacket: False <defaulted>
ChokeThreshold: 100 <defaulted>
DstIpAddr:
DstIpMask: Enabled: False <defaulted>
Appendix B
Troubleshooting
78-15597-02

Advertisement

Table of Contents
loading

Table of Contents