<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to configure syslog on the following IPS module ? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-configure-syslog-on-the-following-ips-module/m-p/2085896#M54224</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can send the log messages to your SIEN using SNMP Traps.&lt;/P&gt;&lt;P&gt;See the DOC: &lt;SPAN style="font-size: 10pt;"&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/cli/cliguide7.html"&gt;http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/cli/cliguide7.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 10 Jan 2013 16:21:52 GMT</pubDate>
    <dc:creator>Rafael Mendes</dc:creator>
    <dc:date>2013-01-10T16:21:52Z</dc:date>
    <item>
      <title>How to configure syslog on the following IPS module ?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-configure-syslog-on-the-following-ips-module/m-p/2085895#M54223</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have IPS modules (ASA-SSM-10) which is installed in Cisco ASA firewall (5520) and i want to integrated the module in RSA Envision log management server. Please confirm if these can be integrated in Envision and how? I am able to recieve Cisco ASA logs by enabling loggin on the box. I need to send logs from this sensor.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below are the module details--&lt;/P&gt;&lt;P&gt;Platform: ASA-SSM-10&lt;BR /&gt;Build Version: 7.0(4)E4&lt;/P&gt;&lt;P&gt;Os Version: 2.4.30-IDS-smp-bigphys&lt;BR /&gt;Can anybody advise me on this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Saurabh Srivastava&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:52:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-configure-syslog-on-the-following-ips-module/m-p/2085895#M54223</guid>
      <dc:creator>Saurabh Srivastava</dc:creator>
      <dc:date>2019-03-10T12:52:01Z</dc:date>
    </item>
    <item>
      <title>How to configure syslog on the following IPS module ?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-configure-syslog-on-the-following-ips-module/m-p/2085896#M54224</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can send the log messages to your SIEN using SNMP Traps.&lt;/P&gt;&lt;P&gt;See the DOC: &lt;SPAN style="font-size: 10pt;"&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/cli/cliguide7.html"&gt;http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/cli/cliguide7.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jan 2013 16:21:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-configure-syslog-on-the-following-ips-module/m-p/2085896#M54224</guid>
      <dc:creator>Rafael Mendes</dc:creator>
      <dc:date>2013-01-10T16:21:52Z</dc:date>
    </item>
    <item>
      <title>How to configure syslog on the following IPS module ?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-configure-syslog-on-the-following-ips-module/m-p/2085897#M54226</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;RSA enVision can be configured to pull these logs using the Cisco's SDEE protocol.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to allow the enVision server to connect to the IPS through an access-list entry in&lt;STRONG&gt; "service host\network-settings"&lt;/STRONG&gt; on the CLI.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From enVision you need to configure the SDEE Collection Service from&lt;STRONG&gt; "Overview\System Configuration\Services\Device Services\Manage SDEE Collection Service"&lt;/STRONG&gt;.&amp;nbsp; When adding a device just give the IP address of the IPS, a user name for enVision to use to connect, password, and port of 443.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One thing to note, this will give you basic alert information but wont include the TriggerPacket details which are often times helpful in alert investigation.&amp;nbsp; You can check if this is the case by opening the &lt;STRONG&gt;"Cisco Secure Ids.txt" &lt;/STRONG&gt;file from the "\&lt;STRONG&gt;nic\csd\config\sdees\templates" &lt;/STRONG&gt;directory and see if it contains &lt;STRONG&gt;"cid:triggerPacket"&lt;/STRONG&gt;.&amp;nbsp; If the file doesn't contain that you can just rename the file to something like "Cisco Secure Ids.old" and then copy the &lt;STRONG&gt;"Cisco Secure Ids.txt"&lt;/STRONG&gt; file from &lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;"%_envision%\etc\devices\ciscoidsxml\sdee"&lt;/STRONG&gt; to "&lt;STRONG&gt;\nic\csd\config\sdees\templates"&lt;/STRONG&gt;.&amp;nbsp; Restart the Collector service and you should be good to go.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One final note, the trigger packet data comes over in base64 format so you will need to run that output through a base64 program or script of some sort.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jan 2013 18:17:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-configure-syslog-on-the-following-ips-module/m-p/2085897#M54226</guid>
      <dc:creator>JonPBerbee</dc:creator>
      <dc:date>2013-01-10T18:17:05Z</dc:date>
    </item>
    <item>
      <title>How to configure syslog on the following IPS module ?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-configure-syslog-on-the-following-ips-module/m-p/2085898#M54228</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for reply..This procedure is for CISCO IPS appliance viz 4240 etc. however i want to integrate ASA-IPS module(SSM module) with RSA envision and i had contacted RSA in this regards and as per them logs will come under ASA logs via syslog but fail to see the IPS logs..&lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_macro_emoticon" height="1" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif" width="1"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please suggest..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Saurabh&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Jan 2013 03:36:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-configure-syslog-on-the-following-ips-module/m-p/2085898#M54228</guid>
      <dc:creator>Saurabh Srivastava</dc:creator>
      <dc:date>2013-01-11T03:36:22Z</dc:date>
    </item>
    <item>
      <title>How to configure syslog on the following IPS module ?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-configure-syslog-on-the-following-ips-module/m-p/2085899#M54229</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does the RSA tool supports SDEE events.&lt;/P&gt;&lt;P&gt;If yes, then it should be pretty straightforward to pull the events.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-12515"&gt;https://supportforums.cisco.com/docs/DOC-12515&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sawan Gupta&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Jan 2013 04:38:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-configure-syslog-on-the-following-ips-module/m-p/2085899#M54229</guid>
      <dc:creator>sawgupta</dc:creator>
      <dc:date>2013-01-11T04:38:41Z</dc:date>
    </item>
    <item>
      <title>How to configure syslog on the following IPS module ?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-configure-syslog-on-the-following-ips-module/m-p/2085900#M54232</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Sawan..i will try it out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards, &lt;BR /&gt;Saurabh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Jan 2013 13:38:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-configure-syslog-on-the-following-ips-module/m-p/2085900#M54232</guid>
      <dc:creator>Saurabh Srivastava</dc:creator>
      <dc:date>2013-01-11T13:38:15Z</dc:date>
    </item>
    <item>
      <title>How to configure syslog on the following IPS module ?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-configure-syslog-on-the-following-ips-module/m-p/2085901#M54234</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Saurabh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The enVision appliances we manage all pull the events from IPS modules in ASA's so the process will work for that as well, as long as you have given the IPS an IP address and have the management port cabled.&amp;nbsp; We have enVision pulling logs via the process I explained from ASA-SSM-10 &amp;amp; ASA5515-IPS devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Jan 2013 15:10:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-configure-syslog-on-the-following-ips-module/m-p/2085901#M54234</guid>
      <dc:creator>JonPBerbee</dc:creator>
      <dc:date>2013-01-11T15:10:40Z</dc:date>
    </item>
  </channel>
</rss>

