<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CLI command output in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cli-command-output/m-p/3918433#M5629</link>
    <description>Ok, so the command "show threat-detection statistics top host" will provide information on top source IP addresses.&lt;BR /&gt;&lt;BR /&gt;HTH</description>
    <pubDate>Tue, 03 Sep 2019 19:43:15 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2019-09-03T19:43:15Z</dc:date>
    <item>
      <title>CLI command output</title>
      <link>https://community.cisco.com/t5/network-security/cli-command-output/m-p/3918368#M5625</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have seen this output but Im not really sure which CLI command is for the ASA to check some sort of top talkers&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what is the CLI command?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:27:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cli-command-output/m-p/3918368#M5625</guid>
      <dc:creator>Kn1ghtR1d3rOfD00m</dc:creator>
      <dc:date>2020-02-21T17:27:17Z</dc:date>
    </item>
    <item>
      <title>Re: CLI command output</title>
      <link>https://community.cisco.com/t5/network-security/cli-command-output/m-p/3918372#M5626</link>
      <description>Hi,&lt;BR /&gt;I would guess that is the output from the command "show threat-detection statistics top port-protocol". You could also use "show local-host connection tcp|udp X" to determine the local-hosts with a specific "X" number of tcp or udp connections, which may be helpful.&lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Tue, 03 Sep 2019 18:15:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cli-command-output/m-p/3918372#M5626</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-09-03T18:15:42Z</dc:date>
    </item>
    <item>
      <title>Re: CLI command output</title>
      <link>https://community.cisco.com/t5/network-security/cli-command-output/m-p/3918373#M5627</link>
      <description>thanks for the info,&lt;BR /&gt;not really sure, in the ouput I shared, there are source IPs, not sure why the guy did not want to share the CLI command &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; selflish&lt;BR /&gt;I have tested now and the first command gives this&lt;BR /&gt;&lt;BR /&gt;Top Name Id Average(eps) Current(eps) Trigger Total events&lt;BR /&gt;20-min Sent attack:&lt;BR /&gt;20-min Recv attack:&lt;BR /&gt;01 Port-8191-65535 308 226 57384 185361&lt;BR /&gt;02 SYSLOG 514 25 30 27625 15283&lt;BR /&gt;03 HTTP-Alternat 8080 19 21 33397 11491&lt;BR /&gt;04 LDAP 389 17 19 43070 10770&lt;BR /&gt;05 NetBIOS-Name 137 5 14 5159 3331&lt;BR /&gt;06 HTTPS 443 4 2 891 2939&lt;BR /&gt;07 DNS 53 3 2 1198 1839&lt;BR /&gt;08 NetBIOS-Datag 138 1 1 2 1056&lt;BR /&gt;09 Port-4438 4438 1 1 0 778&lt;BR /&gt;10 Kerberos-auto 88 1 1 5 688&lt;BR /&gt;1-hour Sent byte:&lt;BR /&gt;01 HTTP-Alternat 8080 5235993 5363390 0 18849575605&lt;BR /&gt;02 HTTPS 443 4564908 4641885 0 16433669917&lt;BR /&gt;03 HTTP 80 3380638 3865723 0 12170298533&lt;BR /&gt;04 Port-8191-65535 2251454 2058040 0 8105234478&lt;BR /&gt;05 EGP * 8 1413754 1386479 0 5089514576&lt;BR /&gt;06 MS-DS/SMB 445 513860 353554&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;and the second command gives me this&lt;BR /&gt;&lt;BR /&gt;Top Name Id Average(eps) Current(eps) Trigger Total events&lt;BR /&gt;20-min Sent attack:&lt;BR /&gt;20-min Recv attack:&lt;BR /&gt;01 Port-8191-65535 310 289 57382 186210&lt;BR /&gt;02 SYSLOG 514 25 28 27624 15016&lt;BR /&gt;03 HTTP-Alternat 8080 19 16 33397 11517&lt;BR /&gt;04 LDAP 389 17 14 43070 10750&lt;BR /&gt;05 HTTPS 443 5 4 891 3528&lt;BR /&gt;06 NetBIOS-Name 137 5 3 5159 3071&lt;BR /&gt;07 DNS 53 3 4 1198 1848&lt;BR /&gt;08 NetBIOS-Datag 138 1 1 2 1060&lt;BR /&gt;09 HTTP 80 1 3 11 817&lt;BR /&gt;10 Port-4438 4438 1 0 0 725&lt;BR /&gt;1-hour Sent byte:&lt;BR /&gt;01 HTTP-Alternat 8080 5235993 5363390 0 18849575605&lt;BR /&gt;02 HTTPS 443 4564908 4641885 0 16433669917&lt;BR /&gt;03 HTTP 80 3380638 3865723 0 12170298533&lt;BR /&gt;04 Port-8191-65535 2251454 2058040 0 8105234478&lt;BR /&gt;05 EGP * 8 1413810 1418093 0 5089716136&lt;BR /&gt;06 MS-DS/SMB 445 513860 353554 0 1849898740&lt;BR /&gt;07 LDAP 389 200988 154814 0 723557647&lt;BR /&gt;08 Port-4001 4001 160531 135467 0 577914419&lt;BR /&gt;09 DNS 53 38978 38616 0 140322645&lt;BR /&gt;10 Port-5246 5246 14915 12851 0 53694288&lt;BR /&gt;1-hour Sent pkts:&lt;BR /&gt;01 HTTP-Alternat 8080 7849 8013 0 28259482&lt;BR /&gt;02 HTTPS 443 5524 5444 0 19887648&lt;BR /&gt;03 Port-8191-65535 2913 2786 0&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;any ideas?</description>
      <pubDate>Tue, 03 Sep 2019 18:21:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cli-command-output/m-p/3918373#M5627</guid>
      <dc:creator>Kn1ghtR1d3rOfD00m</dc:creator>
      <dc:date>2019-09-03T18:21:54Z</dc:date>
    </item>
    <item>
      <title>Re: CLI command output</title>
      <link>https://community.cisco.com/t5/network-security/cli-command-output/m-p/3918433#M5629</link>
      <description>Ok, so the command "show threat-detection statistics top host" will provide information on top source IP addresses.&lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Tue, 03 Sep 2019 19:43:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cli-command-output/m-p/3918433#M5629</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-09-03T19:43:15Z</dc:date>
    </item>
    <item>
      <title>Re: CLI command output</title>
      <link>https://community.cisco.com/t5/network-security/cli-command-output/m-p/3918449#M5631</link>
      <description>thanks, that was it,&lt;BR /&gt;&lt;BR /&gt;yes, not sure why I used sensitive help &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt; think Im burned with a lot of GUI,&lt;BR /&gt;&lt;BR /&gt;thanks so much for your help,</description>
      <pubDate>Tue, 03 Sep 2019 20:00:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cli-command-output/m-p/3918449#M5631</guid>
      <dc:creator>Kn1ghtR1d3rOfD00m</dc:creator>
      <dc:date>2019-09-03T20:00:49Z</dc:date>
    </item>
  </channel>
</rss>

