<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Feedback - CiscoWorks Security Information Management Soluti in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/feedback-ciscoworks-security-information-management-solution/m-p/305974#M1059912</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm interested in this product too, especially its ability to correlate the security activity info from the different sources and not only Cisco based devices such as Snort, UNIX syslogs, however, it seems like it is a bit behind supporting the Snort's version (1.8 now)/signatures, for example.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 15 Oct 2004 20:47:51 GMT</pubDate>
    <dc:creator>dmitry</dc:creator>
    <dc:date>2004-10-15T20:47:51Z</dc:date>
    <item>
      <title>Feedback - CiscoWorks Security Information Management Solution</title>
      <link>https://community.cisco.com/t5/network-security/feedback-ciscoworks-security-information-management-solution/m-p/305972#M1059909</link>
      <description>&lt;P&gt;Can somebody share his experience with&lt;/P&gt;&lt;P&gt;CiscoWorks Security Information Management Solution (CiscoWorks SIMS)?&lt;/P&gt;&lt;P&gt;How do you like it? Is it doing what it is supposed to do well?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:29:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/feedback-ciscoworks-security-information-management-solution/m-p/305972#M1059909</guid>
      <dc:creator>harizanovg</dc:creator>
      <dc:date>2020-02-21T07:29:21Z</dc:date>
    </item>
    <item>
      <title>Re: Feedback - CiscoWorks Security Information Management Soluti</title>
      <link>https://community.cisco.com/t5/network-security/feedback-ciscoworks-security-information-management-solution/m-p/305973#M1059911</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have installed the SIMS 3.1 appliance into a small web hosting network. I have 4 Cisco IDS, 8 routers, and 6 Pix firewalls all reporting to the unit. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am in the process of exploring all the different reports available. So far I am happy with automated reporting capability.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have found that the vast majority of events are due to system misconfiguration, network cleanup, etc. There is definitely a significant effort to tune your reporting devices in order to avoid false positives and other "noise".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am also looking into the Risk Management cabability but the documentation is less than helpful. Apparently the "brute force" method of just diving in and testing all the capabilities of the system is the only way to really learn it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you have any specific questions and I will do my best to answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;JT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Sep 2004 16:13:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/feedback-ciscoworks-security-information-management-solution/m-p/305973#M1059911</guid>
      <dc:creator>joturner</dc:creator>
      <dc:date>2004-09-28T16:13:58Z</dc:date>
    </item>
    <item>
      <title>Re: Feedback - CiscoWorks Security Information Management Soluti</title>
      <link>https://community.cisco.com/t5/network-security/feedback-ciscoworks-security-information-management-solution/m-p/305974#M1059912</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm interested in this product too, especially its ability to correlate the security activity info from the different sources and not only Cisco based devices such as Snort, UNIX syslogs, however, it seems like it is a bit behind supporting the Snort's version (1.8 now)/signatures, for example.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Oct 2004 20:47:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/feedback-ciscoworks-security-information-management-solution/m-p/305974#M1059912</guid>
      <dc:creator>dmitry</dc:creator>
      <dc:date>2004-10-15T20:47:51Z</dc:date>
    </item>
    <item>
      <title>Re: Feedback - CiscoWorks Security Information Management Soluti</title>
      <link>https://community.cisco.com/t5/network-security/feedback-ciscoworks-security-information-management-solution/m-p/305975#M1059913</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have been running SIMS 3.1 in a web hosting environment for the last couple of months. Event sources we are collecting from include Cisco routers, Cisco IDS, PIX firewalls, and we are in the process of setting up the nF Agent for IIS webServer and the TripWire agent. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you have any specific questions about the product and I would be happy to give you my feedback.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;JT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Oct 2004 15:38:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/feedback-ciscoworks-security-information-management-solution/m-p/305975#M1059913</guid>
      <dc:creator>joturner</dc:creator>
      <dc:date>2004-10-18T15:38:19Z</dc:date>
    </item>
    <item>
      <title>Re: Feedback - CiscoWorks Security Information Management Soluti</title>
      <link>https://community.cisco.com/t5/network-security/feedback-ciscoworks-security-information-management-solution/m-p/305976#M1059914</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have purchased the SIMS product, and I need to get up to speed on it as quickly as possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone know of any training courses available for this product?  Or possibly any books or manuals that you could recommend?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- DM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Nov 2004 15:40:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/feedback-ciscoworks-security-information-management-solution/m-p/305976#M1059914</guid>
      <dc:creator>davemit</dc:creator>
      <dc:date>2004-11-30T15:40:43Z</dc:date>
    </item>
    <item>
      <title>Re: Feedback - CiscoWorks Security Information Management Soluti</title>
      <link>https://community.cisco.com/t5/network-security/feedback-ciscoworks-security-information-management-solution/m-p/305977#M1059915</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The only documentation I know of is on the Cisco web site and/or the netForensics website. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://cisco.com/en/US/partner/products/sw/cscowork/ps5209/index.html" target="_blank"&gt;http://cisco.com/en/US/partner/products/sw/cscowork/ps5209/index.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://netforensics.com/" target="_blank"&gt;http://netforensics.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't think there has been anything written by 3rd parties. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Word of caution, the documentation is not very deep at all so you may need to lean on the Cisco TAC for more in depth information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What devices are you planning on collecting security information from?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;JT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Nov 2004 18:27:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/feedback-ciscoworks-security-information-management-solution/m-p/305977#M1059915</guid>
      <dc:creator>joturner</dc:creator>
      <dc:date>2004-11-30T18:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: Feedback - CiscoWorks Security Information Management Soluti</title>
      <link>https://community.cisco.com/t5/network-security/feedback-ciscoworks-security-information-management-solution/m-p/305978#M1059916</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Right now it is all Cisco stuff.  PIX's and routers mainly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to get into the product to see what it can do so I can determine how we can best use it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm primarily interested in the reporting aspect of it, as we manage various security devices for our customers, and I need a way of producing some reports that I can deliver to the customer.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Nov 2004 18:52:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/feedback-ciscoworks-security-information-management-solution/m-p/305978#M1059916</guid>
      <dc:creator>davemit</dc:creator>
      <dc:date>2004-11-30T18:52:16Z</dc:date>
    </item>
  </channel>
</rss>

