<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPS Log Report - Looking for Cisco Solution?? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-log-report-looking-for-cisco-solution/m-p/1729541#M65023</link>
    <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am looking for a cisco solution which can give me schedule mail with IPS log report. Below is what I am looking for,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A) Periodically mail me with IPS log report. such as daily or weekly.&lt;/P&gt;&lt;P&gt;B) The report should include &lt;STRONG&gt;Source addres+Destination Address+Timestamp+SignatureID+SignatureName.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;C) Please see the &lt;STRONG&gt;attchaed file 01&lt;/STRONG&gt; - which I used to get in my previous organization from Cisco VMS. It was a 1 day report for 1 of the IPS back in 11th May 2008.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now here is what I have gone through,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) I am looking for a cisco solution.&lt;/P&gt;&lt;P&gt;2) I have check with IME 7.x. &lt;STRONG&gt;They can not mail report&lt;/STRONG&gt;. But they can generate report on specfic formate. T&lt;STRONG&gt;hese reports are either Source or Destination or Signature based.&lt;/STRONG&gt; I am not able to get the Report like I said above in point no (B).&lt;/P&gt;&lt;P&gt;3) I am currently checking with cisco CSM. Only difference with IME I found is that it can take log from Firewall and It can mail the report periodicaly. But the Report format is still same for IPS.&lt;/P&gt;&lt;P&gt;4) The report generated by IME and CSM are same and not very effective in a sence that it wont have the full information. &lt;STRONG&gt;I mean when [time] "X" type [signature name/ID] attack is happend by "Y" [SourceIP] source to "Z" [Destination IP] destination. &lt;/STRONG&gt;This is what I mean at point (B) which I used to get with VMS.&lt;/P&gt;&lt;P&gt;5) I am not sure whether by CSM I can customize report and get the type of Report that I am looking for. If anyone know that it is possible through CSM please share with me.&lt;/P&gt;&lt;P&gt;6) We have Syslog-NG but we want something viewable for Management's understanding.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please it will be very helpful for me, if anyone can tell me whether cisco currently has a solution which can effectivity report like this type. Please let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks//&lt;/P&gt;&lt;P&gt;Adnan&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 12:22:35 GMT</pubDate>
    <dc:creator>AdnanShahid</dc:creator>
    <dc:date>2019-03-10T12:22:35Z</dc:date>
    <item>
      <title>IPS Log Report - Looking for Cisco Solution??</title>
      <link>https://community.cisco.com/t5/network-security/ips-log-report-looking-for-cisco-solution/m-p/1729541#M65023</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am looking for a cisco solution which can give me schedule mail with IPS log report. Below is what I am looking for,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A) Periodically mail me with IPS log report. such as daily or weekly.&lt;/P&gt;&lt;P&gt;B) The report should include &lt;STRONG&gt;Source addres+Destination Address+Timestamp+SignatureID+SignatureName.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;C) Please see the &lt;STRONG&gt;attchaed file 01&lt;/STRONG&gt; - which I used to get in my previous organization from Cisco VMS. It was a 1 day report for 1 of the IPS back in 11th May 2008.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now here is what I have gone through,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) I am looking for a cisco solution.&lt;/P&gt;&lt;P&gt;2) I have check with IME 7.x. &lt;STRONG&gt;They can not mail report&lt;/STRONG&gt;. But they can generate report on specfic formate. T&lt;STRONG&gt;hese reports are either Source or Destination or Signature based.&lt;/STRONG&gt; I am not able to get the Report like I said above in point no (B).&lt;/P&gt;&lt;P&gt;3) I am currently checking with cisco CSM. Only difference with IME I found is that it can take log from Firewall and It can mail the report periodicaly. But the Report format is still same for IPS.&lt;/P&gt;&lt;P&gt;4) The report generated by IME and CSM are same and not very effective in a sence that it wont have the full information. &lt;STRONG&gt;I mean when [time] "X" type [signature name/ID] attack is happend by "Y" [SourceIP] source to "Z" [Destination IP] destination. &lt;/STRONG&gt;This is what I mean at point (B) which I used to get with VMS.&lt;/P&gt;&lt;P&gt;5) I am not sure whether by CSM I can customize report and get the type of Report that I am looking for. If anyone know that it is possible through CSM please share with me.&lt;/P&gt;&lt;P&gt;6) We have Syslog-NG but we want something viewable for Management's understanding.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please it will be very helpful for me, if anyone can tell me whether cisco currently has a solution which can effectivity report like this type. Please let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks//&lt;/P&gt;&lt;P&gt;Adnan&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:22:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-log-report-looking-for-cisco-solution/m-p/1729541#M65023</guid>
      <dc:creator>AdnanShahid</dc:creator>
      <dc:date>2019-03-10T12:22:35Z</dc:date>
    </item>
    <item>
      <title>IPS Log Report - Looking for Cisco Solution??</title>
      <link>https://community.cisco.com/t5/network-security/ips-log-report-looking-for-cisco-solution/m-p/1729542#M65025</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Adnan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This kind of reporting is not possible to my knowledge.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can send / export your&amp;nbsp; alterts via SNMP traps or any other method and then use a third-party tool to generate such reports e.g. Arcsight logger, Splunk etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both offer free versions (with limitations) that might fit in your scenario.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Jun 2011 13:44:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-log-report-looking-for-cisco-solution/m-p/1729542#M65025</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2011-06-16T13:44:31Z</dc:date>
    </item>
    <item>
      <title>IPS Log Report - Looking for Cisco Solution??</title>
      <link>https://community.cisco.com/t5/network-security/ips-log-report-looking-for-cisco-solution/m-p/1729543#M65026</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It seems this should be a CSM function, but it's not...or not easy to do.&amp;nbsp; Why is that?&amp;nbsp; This seems like a no-brainer...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Oct 2011 16:12:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-log-report-looking-for-cisco-solution/m-p/1729543#M65026</guid>
      <dc:creator>rrfield</dc:creator>
      <dc:date>2011-10-20T16:12:46Z</dc:date>
    </item>
  </channel>
</rss>

