Sensor Events; Show Events Command - Cisco IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor Installation And Configuration Manual

Intrusion detection system appliance and module
Table of Contents

Advertisement

Appendix B
Troubleshooting

Sensor Events

show events Command

Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
This section contains these topics:
Sensor Events, page B-67
show events Command, page B-67
Displaying and Clearing Events, page B-68
show events Command Output, page B-69
There are five types of events:
evAlert—Intrusion detection alerts
evError—Application errors
evStatus—Status changes, such as an IP log being created
evLogTransaction—Record of control transactions processed by each sensor
application
evShunRqst—Block requests
Events remain in the EventStore until they are overwritten by newer events.
The show events command is useful for troubleshooting event capture issues in
which you are not seeing events in IDS Event Viewer or Security Monitor. You
can use the show events command to determine which events are being generated
on the sensor to make sure events are being generated and that the fault lies with
the monitoring side.
You can clear all events from EventStore by using the clear events command.
Here are the parameters for the show events command:
sensor# show events
<cr>
alert
Display local system alerts
error
Display error events
hh:mm[:ss]
Display start time
log
Display log events
Gathering Information
B-67

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor and is the answer not in the manual?

Questions and answers

Table of Contents