<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Log save in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/log-save/m-p/1492781#M67331</link>
    <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to know how to save IPS 4260 logs.&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 12:00:54 GMT</pubDate>
    <dc:creator>mitang.prajapati</dc:creator>
    <dc:date>2019-03-10T12:00:54Z</dc:date>
    <item>
      <title>Log save</title>
      <link>https://community.cisco.com/t5/network-security/log-save/m-p/1492781#M67331</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to know how to save IPS 4260 logs.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:00:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/log-save/m-p/1492781#M67331</guid>
      <dc:creator>mitang.prajapati</dc:creator>
      <dc:date>2019-03-10T12:00:54Z</dc:date>
    </item>
    <item>
      <title>Re: Log save</title>
      <link>https://community.cisco.com/t5/network-security/log-save/m-p/1492782#M67332</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Cisco's IPS sensors allow event retrieval via the Security Device Event Exchange (SDEE) protocol.&amp;nbsp; There are many products that support this protocol.&amp;nbsp; Cisco provides a free solution called IPS Manager Express (IME).&amp;nbsp; It will retrieve signature events from Cisco IPS sensors and store them in a local MySQL database.&amp;nbsp; You can find out more about IME, and download it here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/go/ime"&gt;http://www.cisco.com/go/ime&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another solution, for multiple security device log collection and incident correlation, is CS-MARS.&amp;nbsp; You can find out more about CS-MARS here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/go.mars"&gt;http://www.cisco.com/go.mars&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Jun 2010 10:38:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/log-save/m-p/1492782#M67332</guid>
      <dc:creator>Scott Fringer</dc:creator>
      <dc:date>2010-06-01T10:38:41Z</dc:date>
    </item>
    <item>
      <title>Re: Log save</title>
      <link>https://community.cisco.com/t5/network-security/log-save/m-p/1492783#M67333</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Scott,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any product/tool avialable that our customer can use to pull IPS alarms/event logs via SDEE and save it on a syslog server (kiwi for example) ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Munaf&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jun 2010 06:54:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/log-save/m-p/1492783#M67333</guid>
      <dc:creator>Munaf Ahmed</dc:creator>
      <dc:date>2010-06-02T06:54:49Z</dc:date>
    </item>
    <item>
      <title>Re: Log save</title>
      <link>https://community.cisco.com/t5/network-security/log-save/m-p/1492784#M67334</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Munaf;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; I am not aware of such a product.&amp;nbsp; I have heard of customers using perl scripts, and other custom solutions, to accomplish similar IPS event manipulation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jun 2010 10:28:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/log-save/m-p/1492784#M67334</guid>
      <dc:creator>Scott Fringer</dc:creator>
      <dc:date>2010-06-02T10:28:02Z</dc:date>
    </item>
    <item>
      <title>Re: Log save</title>
      <link>https://community.cisco.com/t5/network-security/log-save/m-p/1492785#M67335</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I did some research, Security Information &amp;amp; Event Management (SIEM) solution provides log management capabilities for Cisco IPS and CS-MARS. Sansage SIEM supports SDEE protocol and it can pull data from Cisco IPS and CS-MARS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin:0in;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:"Times New Roman";
	mso-fareast-theme-font:minor-fareast;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:minor-bidi;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 11pt; font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: #1f497d;"&gt;&lt;A href="http://www.sensage.com/solutions/siem.php?expandable=1"&gt;http://www.sensage.com/solutions/siem.php?expandable=1&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 11pt; font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: #1f497d;"&gt;&lt;A href="http://www.sensage.com/solutions/siem.php?expandable=1"&gt;http://www.sensage.com/solutions/siem.php?expandable=1&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jun 2010 12:06:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/log-save/m-p/1492785#M67335</guid>
      <dc:creator>Munaf Ahmed</dc:creator>
      <dc:date>2010-06-02T12:06:09Z</dc:date>
    </item>
  </channel>
</rss>

