<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPS Aplication-log in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-aplication-log/m-p/1976603#M55051</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;These are maintained by the IPS device itself in a circular buffer in RAM disk partition.&lt;/P&gt;&lt;P&gt;Once the event partition is full, it will start to overwrite over the oldest event.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use some tool which supports SDEE subscription and retrieve the events regularly from the device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sawan Gupta&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 06 Jul 2012 05:06:39 GMT</pubDate>
    <dc:creator>sawgupta</dc:creator>
    <dc:date>2012-07-06T05:06:39Z</dc:date>
    <item>
      <title>IPS Aplication-log</title>
      <link>https://community.cisco.com/t5/network-security/ips-aplication-log/m-p/1976602#M55050</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of our IPS (4260) showing Applicaiton-log 96%, I just need to know where these logs are saved and how to backup these logs.?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also I want to know where is the event logs are saved and is there a way to backup these logs as well?.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate if someone can advise me on the above please.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:43:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-aplication-log/m-p/1976602#M55050</guid>
      <dc:creator>pemasirid</dc:creator>
      <dc:date>2019-03-10T12:43:05Z</dc:date>
    </item>
    <item>
      <title>IPS Aplication-log</title>
      <link>https://community.cisco.com/t5/network-security/ips-aplication-log/m-p/1976603#M55051</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;These are maintained by the IPS device itself in a circular buffer in RAM disk partition.&lt;/P&gt;&lt;P&gt;Once the event partition is full, it will start to overwrite over the oldest event.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use some tool which supports SDEE subscription and retrieve the events regularly from the device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sawan Gupta&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2012 05:06:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-aplication-log/m-p/1976603#M55051</guid>
      <dc:creator>sawgupta</dc:creator>
      <dc:date>2012-07-06T05:06:39Z</dc:date>
    </item>
    <item>
      <title>IPS Aplication-log</title>
      <link>https://community.cisco.com/t5/network-security/ips-aplication-log/m-p/1976604#M55052</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sawan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your time and response to this post. I still have some clarification on this and appreciate if you can advise or provide and url/documents;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-&amp;nbsp; is there's any possibility to delete those files and how.&lt;/P&gt;&lt;P&gt;-&amp;nbsp; if we have SDEE support tools how can we configured to backup those logs to a server..&lt;/P&gt;&lt;P&gt;-&amp;nbsp; if the sensor rebooted will the above logs be deleted.&lt;/P&gt;&lt;P&gt;- i have seen IPS signature has an option send syslog traps, but general acceptance is to that IPS events doesnt support syslog traps, in that case I'm wondering why there's an option in the signature has for syslog.?.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate if you can clarify the above please.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 07 Jul 2012 09:39:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-aplication-log/m-p/1976604#M55052</guid>
      <dc:creator>pemasirid</dc:creator>
      <dc:date>2012-07-07T09:39:40Z</dc:date>
    </item>
    <item>
      <title>IPS Aplication-log</title>
      <link>https://community.cisco.com/t5/network-security/ips-aplication-log/m-p/1976605#M55053</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no way or benefit in deleting those files. Since it is a permanent circular buffer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding SDEE, it is enabled by default. IME can be configured to retreive all the events.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-12515"&gt;https://supportforums.cisco.com/docs/DOC-12515&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The opton under signature action is for SNMP traps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For exporting system logs to syslog server:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://techzone.cisco.com/t5/Intrusion-Preventions-Systems/Exporting-IPS-System-logs-Not-Events-to-a-Sylog-server/ta-p/30683"&gt;https://techzone.cisco.com/t5/Intrusion-Preventions-Systems/Exporting-IPS-System-logs-Not-Events-to-a-Sylog-server/ta-p/30683&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sawan Gupta&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 07 Jul 2012 10:49:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-aplication-log/m-p/1976605#M55053</guid>
      <dc:creator>sawgupta</dc:creator>
      <dc:date>2012-07-07T10:49:50Z</dc:date>
    </item>
    <item>
      <title>IPS Aplication-log</title>
      <link>https://community.cisco.com/t5/network-security/ips-aplication-log/m-p/1976606#M55054</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Sawan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the same requirement of IPS logging to syslog but on a 4215 running on 6.0.6 E4. how do I get to this link you supplied?&lt;/P&gt;&lt;P&gt;&lt;A href="https://techzone.cisco.com/t5/Intrusion-Preventions-Systems/Exporting-IPS-System-logs-Not-Events-to-a-Sylog-server/ta-p/30683"&gt;https://techzone.cisco.com/t5/Intrusion-Preventions-Systems/Exporting-IPS-System-logs-Not-Events-to-a-Sylog-server/ta-p/30683&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;Joe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Aug 2012 19:12:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-aplication-log/m-p/1976606#M55054</guid>
      <dc:creator>joedansereau</dc:creator>
      <dc:date>2012-08-03T19:12:27Z</dc:date>
    </item>
    <item>
      <title>IPS Aplication-log</title>
      <link>https://community.cisco.com/t5/network-security/ips-aplication-log/m-p/1976607#M55055</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here are the manual steps:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Login with service account&lt;/P&gt;&lt;P&gt;- Use command "/sbin/syslogd -m 0 -R &lt;SYSLOG-SERVER-IP&gt;"&lt;/SYSLOG-SERVER-IP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- or add this in /etc/inittab&lt;/P&gt;&lt;PRE&gt;null::sysinit:/sbin/syslogd -m 0 -R &lt;SYSLOG-SERVER-IP&gt;&lt;/SYSLOG-SERVER-IP&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sawan Gupta&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 04 Aug 2012 02:14:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-aplication-log/m-p/1976607#M55055</guid>
      <dc:creator>sawgupta</dc:creator>
      <dc:date>2012-08-04T02:14:27Z</dc:date>
    </item>
    <item>
      <title>IPS Aplication-log</title>
      <link>https://community.cisco.com/t5/network-security/ips-aplication-log/m-p/1976608#M55056</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sawan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;will this send Status and Error events also or only send IPS Alert events configured with the send to syslog option configured on the signature?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Joe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Aug 2012 14:52:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-aplication-log/m-p/1976608#M55056</guid>
      <dc:creator>joedansereau</dc:creator>
      <dc:date>2012-08-06T14:52:00Z</dc:date>
    </item>
  </channel>
</rss>

