<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sorry but the classic Cisco in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-logs-to-syslog/m-p/2701850#M44963</link>
    <description>&lt;P&gt;Sorry but the classic Cisco IPS such as you have only support export via Cisco's proprietary SDEE transport method.&lt;/P&gt;&lt;P&gt;IPS intrusion events on those platforms cannot be sent out by syslog. The reason I've heard why is because UDP is deemed unreliable and insecure for security management.&lt;/P&gt;</description>
    <pubDate>Wed, 06 May 2015 20:01:09 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2015-05-06T20:01:09Z</dc:date>
    <item>
      <title>IPS Logs to Syslog</title>
      <link>https://community.cisco.com/t5/network-security/ips-logs-to-syslog/m-p/2701849#M44961</link>
      <description>&lt;P&gt;We are using IPS Modules AIP SSM 20 in ASA 5520 and software based IPS in 5525-X.&lt;/P&gt;&lt;P&gt;We want to send their logs to an external syslog server. Is that possible ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently IME is managing all the alerts and notifications via emails.&lt;/P&gt;&lt;P&gt;But our requirement is to get IPS logs in external Syslog Server.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:22:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-logs-to-syslog/m-p/2701849#M44961</guid>
      <dc:creator>ummerishtiaq</dc:creator>
      <dc:date>2019-03-10T13:22:20Z</dc:date>
    </item>
    <item>
      <title>Sorry but the classic Cisco</title>
      <link>https://community.cisco.com/t5/network-security/ips-logs-to-syslog/m-p/2701850#M44963</link>
      <description>&lt;P&gt;Sorry but the classic Cisco IPS such as you have only support export via Cisco's proprietary SDEE transport method.&lt;/P&gt;&lt;P&gt;IPS intrusion events on those platforms cannot be sent out by syslog. The reason I've heard why is because UDP is deemed unreliable and insecure for security management.&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2015 20:01:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-logs-to-syslog/m-p/2701850#M44963</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-05-06T20:01:09Z</dc:date>
    </item>
    <item>
      <title>Thanks for the clarification</title>
      <link>https://community.cisco.com/t5/network-security/ips-logs-to-syslog/m-p/2701851#M44964</link>
      <description>&lt;P&gt;Thanks for the clarification.&lt;/P&gt;&lt;P&gt;So is there anyway we can be aware of when someone tries to login to the IPS, do login logs being made for success or denied attempts ?&lt;/P&gt;</description>
      <pubDate>Fri, 08 May 2015 06:54:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-logs-to-syslog/m-p/2701851#M44964</guid>
      <dc:creator>ummerishtiaq</dc:creator>
      <dc:date>2015-05-08T06:54:03Z</dc:date>
    </item>
  </channel>
</rss>

