<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS event store in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-event-store/m-p/1624913#M65566</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Events generated are stored locally in the event store of the IPS.&lt;/P&gt;&lt;P&gt;This event store has limited storage so old events will get overwritten with new ones.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hence we can actually retieve the events from the IPS usind TCP based SDEE protocol if one wishes to store all the events.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-12515"&gt;https://supportforums.cisco.com/docs/DOC-12515&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This can be done using:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. IPS Manager express (IME). Free download on cisco.com&lt;/P&gt;&lt;P&gt;2. MARS&lt;/P&gt;&lt;P&gt;3. External SDEE server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What software are you using to veiw events ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just use IME to view the events from the IPS.&lt;/P&gt;&lt;P&gt;And IME can store events from the IPS locally on the harddrive of the machine on which its installed.&lt;/P&gt;&lt;P&gt;You can filter on simply viewing high sev events.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sid Chandrachud&lt;/P&gt;&lt;P&gt;Cisco TAC&amp;nbsp; - Security Team.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 25 Feb 2011 19:41:32 GMT</pubDate>
    <dc:creator>Siddharth Chandrachud</dc:creator>
    <dc:date>2011-02-25T19:41:32Z</dc:date>
    <item>
      <title>IPS event store</title>
      <link>https://community.cisco.com/t5/network-security/ips-event-store/m-p/1624912#M65565</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have an IPS 4240. We do not have any SNMP logging,but there are many Alterts of High siverity and we would like to know all that is of High sivereity. But when we query the event viewer, it shows only for the last 3 days. Does this mean the logs are getting over written.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; section Cumulative number of each type of event&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Status events 78455&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Shun request events 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Error events, warning 447&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Error events, error 480&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Error events, fatal 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Alert events, informational 2137338&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Alert events, low 60847&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Alert events, medium 292&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Alert events, high 5199&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Alert events, threat rating 0-20 239092&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Alert events, threat rating 21-40 1898253&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Alert events, threat rating 41-60 64126&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Alert events, threat rating 61-80 1413&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Alert events, threat rating 81-100 792&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any way we can get information on all the 792 high siverity of events if they are not sent to any logging server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the capacity of the event store. Can we enable event store that it stores only events of high siverity rather than all informationation events as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tauseef&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:16:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-event-store/m-p/1624912#M65565</guid>
      <dc:creator>tad.190804</dc:creator>
      <dc:date>2019-03-10T12:16:50Z</dc:date>
    </item>
    <item>
      <title>Re: IPS event store</title>
      <link>https://community.cisco.com/t5/network-security/ips-event-store/m-p/1624913#M65566</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Events generated are stored locally in the event store of the IPS.&lt;/P&gt;&lt;P&gt;This event store has limited storage so old events will get overwritten with new ones.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hence we can actually retieve the events from the IPS usind TCP based SDEE protocol if one wishes to store all the events.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-12515"&gt;https://supportforums.cisco.com/docs/DOC-12515&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This can be done using:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. IPS Manager express (IME). Free download on cisco.com&lt;/P&gt;&lt;P&gt;2. MARS&lt;/P&gt;&lt;P&gt;3. External SDEE server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What software are you using to veiw events ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just use IME to view the events from the IPS.&lt;/P&gt;&lt;P&gt;And IME can store events from the IPS locally on the harddrive of the machine on which its installed.&lt;/P&gt;&lt;P&gt;You can filter on simply viewing high sev events.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sid Chandrachud&lt;/P&gt;&lt;P&gt;Cisco TAC&amp;nbsp; - Security Team.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Feb 2011 19:41:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-event-store/m-p/1624913#M65566</guid>
      <dc:creator>Siddharth Chandrachud</dc:creator>
      <dc:date>2011-02-25T19:41:32Z</dc:date>
    </item>
  </channel>
</rss>

