Appendix B
Troubleshooting
Sensor Events
show events Command
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
This section contains these topics:
•
Sensor Events, page B-67
show events Command, page B-67
•
•
Displaying and Clearing Events, page B-68
show events Command Output, page B-69
•
There are five types of events:
evAlert—Intrusion detection alerts
•
•
evError—Application errors
evStatus—Status changes, such as an IP log being created
•
•
evLogTransaction—Record of control transactions processed by each sensor
application
•
evShunRqst—Block requests
Events remain in the EventStore until they are overwritten by newer events.
The show events command is useful for troubleshooting event capture issues in
which you are not seeing events in IDS Event Viewer or Security Monitor. You
can use the show events command to determine which events are being generated
on the sensor to make sure events are being generated and that the fault lies with
the monitoring side.
You can clear all events from EventStore by using the clear events command.
Here are the parameters for the show events command:
sensor# show events
<cr>
alert
Display local system alerts
error
Display error events
hh:mm[:ss]
Display start time
log
Display log events
Gathering Information
B-67
Need help?
Do you have a question about the IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor and is the answer not in the manual?
Questions and answers