<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi,Event Critical : Lets you in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/event-retrieval-issue/m-p/2679474#M44897</link>
    <description>&lt;P&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;Hi,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="color: rgb(0, 0, 0); line-height: normal; text-indent: -24px;"&gt;Event Critical : Lets you set a threshold for when the last event was retrieved and whether this metric is applied to the overall sensor health rating.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;http://www.cisco.com/c/en/us/td/docs/security/ips/7-0/configuration/guide/idm/idmguide7/idm_sensor_management.html#wpxref98287&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;FONT style="line-height: normal;"&gt;This health parameter allows us to set a threshold for when the last event was retrieved from the sensor. The health status is degraded to yellow or red depending on the time interval that has been configured for corresponding thresholds. The range of threshold is 0 to 4294967295 seconds.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="color: rgb(102, 102, 102); line-height: 15px;"&gt;Check the show tech from the IPS/AIP and search for “Health Status for the Time Since Last Event Retrieval”, it should be showing RED as well. As we know IDM cannot pull events from the IPS/AIP directly and we will need IME for that, so if the events were not polled for an amount of time (default of 300 for yellow status) and (default of 600 sec for RED), the event status will change colors.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="color: rgb(102, 102, 102); line-height: 15px;"&gt;So it's either Event Retrieval is enabled and the IME is not installed, hence no events are being polled, then this error can be ignored and the event polling can be disabled safely (un-check the Event Retrieval checkbox), OR the IME is not operating as it should and there might be communication issue between the device and the IME.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;Or if it is giving a certificate error or something check 'show version and see if the Host certificate has expired(mentioned at last of show version). If yes, then run the command 'tls generate-key'.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size: 14px;"&gt;Please let me know if you have any query on this.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;Regards,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;Akshay Rastogi&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 03 Jun 2015 02:49:55 GMT</pubDate>
    <dc:creator>Akshay Rastogi</dc:creator>
    <dc:date>2015-06-03T02:49:55Z</dc:date>
    <item>
      <title>Event Retrieval Issue</title>
      <link>https://community.cisco.com/t5/network-security/event-retrieval-issue/m-p/2679473#M44896</link>
      <description>&lt;P&gt;I noticed that the sensor health on IPS showing "Critical".&lt;/P&gt;&lt;P&gt;And I clicked for the details, it showed the event retrieval is critical and not retrieved now. I don't know what does&amp;nbsp;that mean.&lt;/P&gt;&lt;P&gt;Can anyone tell me what causes this information and how to fix it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:23:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/event-retrieval-issue/m-p/2679473#M44896</guid>
      <dc:creator>c1szhibin</dc:creator>
      <dc:date>2019-03-10T13:23:26Z</dc:date>
    </item>
    <item>
      <title>Hi,Event Critical : Lets you</title>
      <link>https://community.cisco.com/t5/network-security/event-retrieval-issue/m-p/2679474#M44897</link>
      <description>&lt;P&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;Hi,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="color: rgb(0, 0, 0); line-height: normal; text-indent: -24px;"&gt;Event Critical : Lets you set a threshold for when the last event was retrieved and whether this metric is applied to the overall sensor health rating.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;http://www.cisco.com/c/en/us/td/docs/security/ips/7-0/configuration/guide/idm/idmguide7/idm_sensor_management.html#wpxref98287&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;FONT style="line-height: normal;"&gt;This health parameter allows us to set a threshold for when the last event was retrieved from the sensor. The health status is degraded to yellow or red depending on the time interval that has been configured for corresponding thresholds. The range of threshold is 0 to 4294967295 seconds.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="color: rgb(102, 102, 102); line-height: 15px;"&gt;Check the show tech from the IPS/AIP and search for “Health Status for the Time Since Last Event Retrieval”, it should be showing RED as well. As we know IDM cannot pull events from the IPS/AIP directly and we will need IME for that, so if the events were not polled for an amount of time (default of 300 for yellow status) and (default of 600 sec for RED), the event status will change colors.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="color: rgb(102, 102, 102); line-height: 15px;"&gt;So it's either Event Retrieval is enabled and the IME is not installed, hence no events are being polled, then this error can be ignored and the event polling can be disabled safely (un-check the Event Retrieval checkbox), OR the IME is not operating as it should and there might be communication issue between the device and the IME.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;Or if it is giving a certificate error or something check 'show version and see if the Host certificate has expired(mentioned at last of show version). If yes, then run the command 'tls generate-key'.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size: 14px;"&gt;Please let me know if you have any query on this.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;Regards,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;Akshay Rastogi&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2015 02:49:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/event-retrieval-issue/m-p/2679474#M44897</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-06-03T02:49:55Z</dc:date>
    </item>
    <item>
      <title>After I run the command "tls</title>
      <link>https://community.cisco.com/t5/network-security/event-retrieval-issue/m-p/2679475#M44898</link>
      <description>&lt;P&gt;After I run the command "tls generate-key" , the notification still exists.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2015 07:27:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/event-retrieval-issue/m-p/2679475#M44898</guid>
      <dc:creator>c1szhibin</dc:creator>
      <dc:date>2015-06-11T07:27:18Z</dc:date>
    </item>
    <item>
      <title>Hi,Are are getting this</title>
      <link>https://community.cisco.com/t5/network-security/event-retrieval-issue/m-p/2679476#M44899</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Are are getting this Critical on IDM or IME? as i have mentioned in the last reply that the IDM would show this Event as Critical as it does not pull Events from IPS directly and it need IME to do so.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Akshay Rastogi&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2015 08:14:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/event-retrieval-issue/m-p/2679476#M44899</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-06-11T08:14:12Z</dc:date>
    </item>
    <item>
      <title>I think it's on IDM. There is</title>
      <link>https://community.cisco.com/t5/network-security/event-retrieval-issue/m-p/2679477#M44902</link>
      <description>I think it's on IDM. There is only one IPS running.</description>
      <pubDate>Mon, 15 Jun 2015 05:41:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/event-retrieval-issue/m-p/2679477#M44902</guid>
      <dc:creator>c1szhibin</dc:creator>
      <dc:date>2015-06-15T05:41:43Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/event-retrieval-issue/m-p/2679478#M44903</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;In that case, this Event Retrieval&amp;nbsp;can be ignored as mentioned in the last Reply. You need IME to pull Events. &amp;nbsp;It is not causing any issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;

&lt;PRE style="font-size: 14.3999996185303px; background-color: rgb(249, 249, 249);"&gt;
&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size: 14px;"&gt;&lt;SPAN style="color: rgb(102, 102, 102); line-height: 15px;"&gt; As we know IDM cannot pull events from the IPS/AIP directly and we will need IME for that, so if the events were not polled for an amount of time (default of 300 for yellow status) and (default of 600 sec for RED), the event status will change colors.&lt;/SPAN&gt;&lt;/SPAN&gt;

&lt;SPAN style="font-size: 14px;"&gt;&lt;SPAN style="color: rgb(102, 102, 102); line-height: 15px;"&gt;So it's either Event Retrieval is enabled and the IME is not installed, hence no events are being polled, then this error can be ignored and the event polling can be disabled safely (un-check the Event Retrieval checkbox), OR the IME is not operating as it should and there might be communication issue between the device and the IME.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/PRE&gt;

&lt;P style="font-size: 14.3999996185303px; background-color: rgb(249, 249, 249);"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="font-size: 14.3999996185303px; background-color: rgb(249, 249, 249);"&gt;Please let me know if you have any further query on this. If this answers your query, I&amp;nbsp;would request you to select the appropriate response as the solution for this thread.&lt;/P&gt;
&lt;P style="font-size: 14.3999996185303px; background-color: rgb(249, 249, 249);"&gt;Regards.&lt;/P&gt;
&lt;P style="font-size: 14.3999996185303px; background-color: rgb(249, 249, 249);"&gt;Akshay Rastogi&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2015 11:13:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/event-retrieval-issue/m-p/2679478#M44903</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-06-15T11:13:44Z</dc:date>
    </item>
    <item>
      <title>Thank you for ur kindness.</title>
      <link>https://community.cisco.com/t5/network-security/event-retrieval-issue/m-p/2679479#M44904</link>
      <description>&lt;P&gt;Thank you for ur kindness. After what u said, the following is my solution.&lt;/P&gt;&lt;P&gt;Configuration -&amp;gt; IPS -&amp;gt; Sensor Management -&amp;gt; Sensor Health&lt;/P&gt;&lt;P&gt;no tick the box of&amp;nbsp;“Event Retreval”&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2015 08:50:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/event-retrieval-issue/m-p/2679479#M44904</guid>
      <dc:creator>c1szhibin</dc:creator>
      <dc:date>2015-06-29T08:50:45Z</dc:date>
    </item>
  </channel>
</rss>

