<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS 4255 not logging in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-4255-not-logging/m-p/1507195#M66454</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;George;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Let me try to address your many questions in order:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You indicate not being able to see logs within IME, but you do see them on the IPS-4255's CLI:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt; does IME indicate the "Event Status" is connected?&lt;/LI&gt;&lt;LI&gt;when you added the IPS-4255 to IME, did you check any of the severity levels in bottom section of the device properties?&amp;nbsp; If so, this instructs IME to not retrieve events of that severity.&lt;/LI&gt;&lt;LI&gt;are you able to see real-time events but not historical events within IME?&lt;BR /&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You indicate you attempted deny traffic using the "Deny Packet Inline" action:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;is the IPS-4255 configured for inline operation?&amp;nbsp; Deny actions are only actionable when the IPS-4255 is configured for inline operation, not promiscuous operation.&lt;/LI&gt;&lt;LI&gt;if an event was logged to IME it should include any actions taken, or configured and not taken, in the event details.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; The IPS-4255 will only log traffic for signature events that are triggered, if the signature event triggers for a host that is included in the 'never block' list, it should be logged.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 28 Sep 2010 10:37:30 GMT</pubDate>
    <dc:creator>Scott Fringer</dc:creator>
    <dc:date>2010-09-28T10:37:30Z</dc:date>
    <item>
      <title>IPS 4255 not logging</title>
      <link>https://community.cisco.com/t5/network-security/ips-4255-not-logging/m-p/1507194#M66452</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have installed IPS 4255 with version 7.0(2)E4 and using IME 7.0.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i am not able to see the logs in the IME (Event Monitoring), but when i access it by CLI (show events) i can see the logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i also tried to tune a signature for ICMP large packet to log and deny traffic (using deny packet inlne and deny attaker inline), and ping&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;a server from inside to outside with a large packet. In this case, IME showed the logs but it did not deny the traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i am missing something here ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One more question, does IPS at least log the traffic for ip that are configured for "never block ip addresses"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please i need some help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you and Regards,&lt;/P&gt;&lt;P&gt;George&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:08:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-4255-not-logging/m-p/1507194#M66452</guid>
      <dc:creator>gaboughanem</dc:creator>
      <dc:date>2019-03-10T12:08:17Z</dc:date>
    </item>
    <item>
      <title>Re: IPS 4255 not logging</title>
      <link>https://community.cisco.com/t5/network-security/ips-4255-not-logging/m-p/1507195#M66454</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;George;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Let me try to address your many questions in order:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You indicate not being able to see logs within IME, but you do see them on the IPS-4255's CLI:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt; does IME indicate the "Event Status" is connected?&lt;/LI&gt;&lt;LI&gt;when you added the IPS-4255 to IME, did you check any of the severity levels in bottom section of the device properties?&amp;nbsp; If so, this instructs IME to not retrieve events of that severity.&lt;/LI&gt;&lt;LI&gt;are you able to see real-time events but not historical events within IME?&lt;BR /&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You indicate you attempted deny traffic using the "Deny Packet Inline" action:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;is the IPS-4255 configured for inline operation?&amp;nbsp; Deny actions are only actionable when the IPS-4255 is configured for inline operation, not promiscuous operation.&lt;/LI&gt;&lt;LI&gt;if an event was logged to IME it should include any actions taken, or configured and not taken, in the event details.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; The IPS-4255 will only log traffic for signature events that are triggered, if the signature event triggers for a host that is included in the 'never block' list, it should be logged.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Sep 2010 10:37:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-4255-not-logging/m-p/1507195#M66454</guid>
      <dc:creator>Scott Fringer</dc:creator>
      <dc:date>2010-09-28T10:37:30Z</dc:date>
    </item>
    <item>
      <title>Re: IPS 4255 not logging</title>
      <link>https://community.cisco.com/t5/network-security/ips-4255-not-logging/m-p/1507196#M66456</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Scott,&lt;/P&gt;&lt;P&gt;Thank you for your reply and i will answer the questions that you asked for.&lt;/P&gt;&lt;P&gt;1- yes the Event status shows connected&lt;/P&gt;&lt;P&gt;2- in the Event Monitoring , i have checked all 4 levels to be retrieved by IME.&lt;/P&gt;&lt;P&gt;3- i did not checked for historical events, due to the fact that logs are not being shown in the IME Event Monitoring&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Actually i can see very shy events in the IME every few hours but with IPv6 as source and destination. I don't know&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; where it is coming from, the whole network is IPv4. while on the CLI i can see many many events (using show events).&lt;/P&gt;&lt;P&gt;4- The IPS is configured as inline and promiscuous.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry but i did not undestand the last sentence: "The IPS-4255 will only log traffic for signature events that are&amp;nbsp; triggered, if the signature event triggers for a host that is included&amp;nbsp; in the 'never block' list, it should be logged"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you mean that only events that are triggered are logged and if the ip address is in the "never block address" the IPS will not log it,&amp;nbsp; since it will not fire any signature for that ip address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i am posting the configuration if this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you in advance for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards,&lt;/P&gt;&lt;P&gt;George&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Sep 2010 15:09:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-4255-not-logging/m-p/1507196#M66456</guid>
      <dc:creator>gaboughanem</dc:creator>
      <dc:date>2010-09-28T15:09:49Z</dc:date>
    </item>
    <item>
      <title>Re: IPS 4255 not logging</title>
      <link>https://community.cisco.com/t5/network-security/ips-4255-not-logging/m-p/1507197#M66458</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;George;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; 1- OK, it's good that the event status is connected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2- By checking all four severities in the device properties you have instructed IME &lt;STRONG&gt;not&lt;/STRONG&gt; to retrieve events of those four severities.&amp;nbsp; You need to uncheck those severities to allow IME to retrieve all event severities.&amp;nbsp; Please note, the text with IME is worded,"Exclude alerts of the following severity level(s)".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; 3- If there are no real-time events, you will likely not have historical events.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; 4- As your sensor is configured for both&amp;nbsp; inline and promiscuous operation, the deny&amp;nbsp; actions will only take&amp;nbsp; effect on signature events generated by the inline interface pair.&amp;nbsp; If&amp;nbsp; the signature event is generated by the promiscuous interface, the deny&amp;nbsp; action cannot be actioned.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; While your network may be completely IPv4; it is possible for systems running Windows and Mac OS X to have IPv6 enabled by default, and in turn generate this traffic on your network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; If a signature event fires and has an action of 'Produce Alert' assigned, the IPS should log the activity regardless of the host being listed as do not block or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Sep 2010 15:26:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-4255-not-logging/m-p/1507197#M66458</guid>
      <dc:creator>Scott Fringer</dc:creator>
      <dc:date>2010-09-28T15:26:19Z</dc:date>
    </item>
    <item>
      <title>Re: IPS 4255 not logging</title>
      <link>https://community.cisco.com/t5/network-security/ips-4255-not-logging/m-p/1507198#M66461</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Scott ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have unchecked the information severity to allow IME to retrieve all event severities. i don't know why i have checked it in the first place, but the logs became visible in the IME. i don't know why 98% of the firing signature are informational ?&amp;nbsp; Maybe because the IPS is installed behine an ASA!!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;one more question if not too much trouble, if i close the IME will the logs be lost? how much the IPS keeps the logs before it override new ones?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway thank you very much for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;George&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Oct 2010 17:09:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-4255-not-logging/m-p/1507198#M66461</guid>
      <dc:creator>gaboughanem</dc:creator>
      <dc:date>2010-10-05T17:09:47Z</dc:date>
    </item>
    <item>
      <title>Re: IPS 4255 not logging</title>
      <link>https://community.cisco.com/t5/network-security/ips-4255-not-logging/m-p/1507199#M66466</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;George;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; I'm glad you were able to get the event retrieval corrected, and are now seeing events within IME.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; In regard to your follow-on question; IME has two (2) services that run regardless of whether the GUI is running or not.&amp;nbsp; The two services are the 'Cisco IPS Manager Express Service' and the 'MySQL-IME' service.&amp;nbsp; The first service retreives events from the sensor as long as the Windows host system has connectivity to the managed sensor.&amp;nbsp; The second service is the database service which maintains the IME event database.&amp;nbsp; IME defaults to saving 1,000,000,000 events per database file, with a default of 100 files (these values are configurable).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; The IPS sensor itself has a ~32 MB circular buffer which holds events locally; once full it will begin overwriting older events.&amp;nbsp; As long as the IME service is pulling events, this should not be an issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Oct 2010 17:45:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-4255-not-logging/m-p/1507199#M66466</guid>
      <dc:creator>Scott Fringer</dc:creator>
      <dc:date>2010-10-05T17:45:19Z</dc:date>
    </item>
  </channel>
</rss>

