<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AIP-SSM-20 to send Syslog messages in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/aip-ssm-20-to-send-syslog-messages/m-p/1615496#M65581</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can find it in syslog from ASA.&lt;/P&gt;&lt;P&gt;It will look like this : %ASA-4-420003: IPS requested to reset TCP connection from&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suppose, this is enough.&lt;/P&gt;&lt;P&gt;But from IPS module - as TACman said...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 25 Feb 2011 13:45:08 GMT</pubDate>
    <dc:creator>Pavel Pokorny</dc:creator>
    <dc:date>2011-02-25T13:45:08Z</dc:date>
    <item>
      <title>AIP-SSM-20 to send Syslog messages</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-20-to-send-syslog-messages/m-p/1615492#M65577</link>
      <description>&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to find out if there is any means of configuring my AIP-SSM-20 to generate and send a syslog message whenever it blocks a connection, drops a packet or find any anomaly traffic traversing through it from either the Internet or the Internal network. For audit reasons, my management wants to see this logs send to a syslog server. I have been trying to use IME( IPS Manager Express) to configure this but have not seen any option relating to Syslogs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please if there is a means, let me know and also give me instructions on how to do it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would be greatful for your assistance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Claude Fozao&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:16:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-20-to-send-syslog-messages/m-p/1615492#M65577</guid>
      <dc:creator>claude.fozao</dc:creator>
      <dc:date>2019-03-10T12:16:39Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM-20 to send Syslog messages</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-20-to-send-syslog-messages/m-p/1615493#M65578</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, unfortunately the Cisco IPS events are in Cisco proprietary format, hence there is no option to actually send those events through syslog messages.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Feb 2011 06:58:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-20-to-send-syslog-messages/m-p/1615493#M65578</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-02-24T06:58:32Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM-20 to send Syslog messages</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-20-to-send-syslog-messages/m-p/1615494#M65579</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jennifer,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your prompt response. In this case, is there a way to retrive all the past events from the event store. I believe that this events are saved in an event store which can be retrived and analysed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Feb 2011 07:30:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-20-to-send-syslog-messages/m-p/1615494#M65579</guid>
      <dc:creator>claude.fozao</dc:creator>
      <dc:date>2011-02-24T07:30:24Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM-20 to send Syslog messages</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-20-to-send-syslog-messages/m-p/1615495#M65580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Syslog is UDP based. A packet if lost cannot be re-transmitted.&lt;/P&gt;&lt;P&gt;For event retrieval, not convenient. Does not achieve guaranteed data transfer.&lt;/P&gt;&lt;P&gt;Not the best option if all data has to be recorded for audit purposes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hence for IPS the event retrieval is done via SDEE protocol which is TCP based.&lt;/P&gt;&lt;P&gt;SDEE is not Cisco Proprietary.&amp;nbsp; &lt;SPAN id="search"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-12515"&gt;https://supportforums.cisco.com/docs/DOC-12515&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The IPS events are stored in its own event store.&lt;/P&gt;&lt;P&gt;The capacity of this event store is limited and old events can get overwritten.&lt;/P&gt;&lt;P&gt;Hence IPS requires a device to retrieve events from its event store if you wish to store all the events.&lt;/P&gt;&lt;P&gt;IME can retrieve events from the IPS event store and store it locally.&lt;/P&gt;&lt;P&gt;IME installs a my-sql database on the machine.&lt;/P&gt;&lt;P&gt;You can store upto 400 archive files each containing max 1 million events.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sid Chandrachud&lt;/P&gt;&lt;P&gt;TAC Security Solutions&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Feb 2011 07:46:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-20-to-send-syslog-messages/m-p/1615495#M65580</guid>
      <dc:creator>Siddharth Chandrachud</dc:creator>
      <dc:date>2011-02-24T07:46:21Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM-20 to send Syslog messages</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-20-to-send-syslog-messages/m-p/1615496#M65581</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can find it in syslog from ASA.&lt;/P&gt;&lt;P&gt;It will look like this : %ASA-4-420003: IPS requested to reset TCP connection from&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suppose, this is enough.&lt;/P&gt;&lt;P&gt;But from IPS module - as TACman said...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Feb 2011 13:45:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-20-to-send-syslog-messages/m-p/1615496#M65581</guid>
      <dc:creator>Pavel Pokorny</dc:creator>
      <dc:date>2011-02-25T13:45:08Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM-20 to send Syslog messages</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-20-to-send-syslog-messages/m-p/1615497#M65582</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Pavel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That worked for me. I decided to log message IDs 420002 and 420003.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 Feb 2011 12:39:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-20-to-send-syslog-messages/m-p/1615497#M65582</guid>
      <dc:creator>claude.fozao</dc:creator>
      <dc:date>2011-02-26T12:39:33Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM-20 to send Syslog messages</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-20-to-send-syslog-messages/m-p/1615498#M65583</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Claude,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good to hear advice helped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please sign if problem solved for you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;&lt;H1&gt;&lt;/H1&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 Feb 2011 18:17:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-20-to-send-syslog-messages/m-p/1615498#M65583</guid>
      <dc:creator>Pavel Pokorny</dc:creator>
      <dc:date>2011-02-26T18:17:39Z</dc:date>
    </item>
    <item>
      <title>AIP-SSM-20 to send Syslog messages</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-20-to-send-syslog-messages/m-p/1615499#M65584</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sid Chandrachud,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hence IPS requires a device to retrieve events from its event store if you wish to store all the events.&lt;/P&gt;&lt;P&gt;May I know what device is needed to archive all the events? &lt;/P&gt;&lt;P&gt;Can it be a normal linux or windows server to store the SDEE events? if possbile how to configure the IPS to send events to external servers?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Ryan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jan 2012 14:11:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-20-to-send-syslog-messages/m-p/1615499#M65584</guid>
      <dc:creator>ryanhoibm</dc:creator>
      <dc:date>2012-01-11T14:11:53Z</dc:date>
    </item>
  </channel>
</rss>

