<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Packet Decodes in Alerts in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/packet-decodes-in-alerts/m-p/1409000#M68116</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are two types of packet captures on the IPS Sensors. The one you may be looking at&lt;/P&gt;&lt;P&gt;is included in the alert. This is set by selecting the "produce-verbose-alert" option on the associated signature. There are no further options for this method of packet capture.&lt;/P&gt;&lt;P&gt;The second way of performing packet captures are is the "log-attacter-packets" and "log-victim-packets" (select these as a pair). They will create a PCAP file on the sensor with X number of packets captured. X is settable on a global basis for all signature captures (not on a sig by sig basis).&lt;/P&gt;&lt;P&gt;You can see alerts no the CLI with these commands:&lt;/P&gt;&lt;P&gt;show events alert past 01:00 (to see alerts for the past hour + current alerts as they roll in)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 21 Jan 2010 17:07:29 GMT</pubDate>
    <dc:creator>rhermes</dc:creator>
    <dc:date>2010-01-21T17:07:29Z</dc:date>
    <item>
      <title>Packet Decodes in Alerts</title>
      <link>https://community.cisco.com/t5/network-security/packet-decodes-in-alerts/m-p/1408999#M68114</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to turn on and dictate the length of packet decodes on the sensor?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example I do not get a decode for invalid netbios name(3357), but do for Windows Image color Management (6984).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;exmaple:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; context:&amp;nbsp;&amp;nbsp; &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; fromAttacker: &lt;BR /&gt;000000&amp;nbsp; 0E 30 00 00 00 00 00 00&amp;nbsp; 02 00 00 00 01 00 01 00&amp;nbsp; .0..............&lt;BR /&gt;000010&amp;nbsp; 00 00 00 00 00 00 20 07&amp;nbsp; 67 40 63 00 65 30 6E 00&amp;nbsp; ...... .g@c.e0n.&lt;BR /&gt;000020&amp;nbsp; 74 00 6C 00 79 00 20 00&amp;nbsp; 75 00 01 00 00 04 00 00&amp;nbsp; t.l.y. .u.......&lt;BR /&gt;000030&amp;nbsp; 00 00 20 07 4B C8 00 30&amp;nbsp; 0F 30 00 00 00 00 00 00&amp;nbsp; .. .K..0.0......&lt;BR /&gt;000040&amp;nbsp; 02 00 00 00 0B 00 01 00&amp;nbsp; 00 00 00 00 00 00 20 07&amp;nbsp; .............. .&lt;BR /&gt;000050&amp;nbsp; 4B C8 00 30 0F 30 00 00&amp;nbsp; 00 00 00 00 02 00 00 00&amp;nbsp; K..0.0..........&lt;BR /&gt;000060&amp;nbsp; 0B 00 01 00 00 00 00 00&amp;nbsp; 00 00 20 07 4B C8 00 30&amp;nbsp; .......... .K..0&lt;BR /&gt;000070&amp;nbsp; 0F 30 00 00 00 00 00 00&amp;nbsp; 02 00 00 00 0B 00 01 00&amp;nbsp; .0..............&lt;BR /&gt;000080&amp;nbsp; 00 00 00 00 00 00 20 07&amp;nbsp; 4B C8 00 30 0F 30 00 00&amp;nbsp; ...... .K..0.0..&lt;BR /&gt;000090&amp;nbsp; 00 00 00 00 02 00 00 00&amp;nbsp; 0B 00 01 00 00 04 00 00&amp;nbsp; ................&lt;BR /&gt;0000A0&amp;nbsp; 00 00 20 07 4B C8 00 30&amp;nbsp; 08 30 00 00 00 00 00 00&amp;nbsp; .. .K..0.0......&lt;BR /&gt;0000B0&amp;nbsp; 02 00 00 00 01 00 01 00&amp;nbsp; 00 00 00 00 00 00 20 07&amp;nbsp; .............. .&lt;BR /&gt;0000C0&amp;nbsp; 4B C8 00 30 0F 30 00 00&amp;nbsp; 00 00 00 00 02 00 00 00&amp;nbsp; K..0.0..........&lt;BR /&gt;0000D0&amp;nbsp; 0B 00 01 00 00 00 00 00&amp;nbsp; 00 00 20 07 4B C8 00 30&amp;nbsp; .......... .K..0&lt;BR /&gt;0000E0&amp;nbsp; 0F 30 00 00 00 00 00 00&amp;nbsp; 02 00 00 00 0B 00 01 00&amp;nbsp; .0..............&lt;BR /&gt;0000F0&amp;nbsp; 00 00 00 00 00 00 20 07&amp;nbsp; 6F 40 64 00 65 30 3A 00&amp;nbsp; ...... .o@d.e0:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; fromTarget: &lt;BR /&gt;000000&amp;nbsp; 73 65 3F 73 65 73 73 69&amp;nbsp; 6F 6E 69 64 3D 43 46 30&amp;nbsp; se?sessionid=CF0&lt;BR /&gt;000010&amp;nbsp; 32 42 30 31 39 41 49 44&amp;nbsp; 5F 30 30 30 30 30 35 33&amp;nbsp; 2B019AID_0000053&lt;BR /&gt;000020&amp;nbsp; 32 38 30 30 35 30 30 30&amp;nbsp; 30 30 30 30 30 26 63 61&amp;nbsp; 2800500000000&amp;amp;ca&lt;BR /&gt;000030&amp;nbsp; 73 65 69 64 3D 35 30 34&amp;nbsp; 39 38 34 26 63 61 73 65&amp;nbsp; seid=504984&amp;amp;case&lt;BR /&gt;000040&amp;nbsp; 74 72 61 6E 73 66 65 72&amp;nbsp; 66 6C 61 67 3D 59 0D 0A&amp;nbsp; transferflag=Y..&lt;BR /&gt;000050&amp;nbsp; 41 63 63 65 70 74 2D 4C&amp;nbsp; 61 6E 67 75 61 67 65 3A&amp;nbsp; Accept-Language:&lt;BR /&gt;000060&amp;nbsp; 20 65 6E 2D 67 62 0D 0A&amp;nbsp; 41 63 63 65 70 74 2D 45&amp;nbsp;&amp;nbsp; en-gb..Accept-E&lt;BR /&gt;000070&amp;nbsp; 6E 63 6F 64 69 6E 67 3A&amp;nbsp; 20 67 7A 69 70 2C 20 64&amp;nbsp; ncoding: gzip, d&lt;BR /&gt;000080&amp;nbsp; 65 66 6C 61 74 65 0D 0A&amp;nbsp; 55 73 65 72 2D 41 67 65&amp;nbsp; eflate..User-Age&lt;BR /&gt;000090&amp;nbsp; 6E 74 3A 20 4D 6F 7A 69&amp;nbsp; 6C 6C 61 2F 34 2E 30 20&amp;nbsp; nt: Mozilla/4.0 &lt;BR /&gt;0000A0&amp;nbsp; 28 63 6F 6D 70 61 74 69&amp;nbsp; 62 6C 65 3B 20 4D 53 49&amp;nbsp; (compatible; MSI&lt;BR /&gt;0000B0&amp;nbsp; 45 20 36 2E 30 3B 20 57&amp;nbsp; 69 6E 64 6F 77 73 20 4E&amp;nbsp; E 6.0; Windows N&lt;BR /&gt;0000C0&amp;nbsp; 54 20 35 2E 31 3B 20 53&amp;nbsp; 56 31 3B 20 47 54 42 36&amp;nbsp; T 5.1; SV1; GTB6&lt;BR /&gt;0000D0&amp;nbsp; 29 0D 0A 48 6F 73 74 3A&amp;nbsp; 20 31 30 2E 32 33 32 2E&amp;nbsp; )..Host: 10.232.&lt;BR /&gt;0000E0&amp;nbsp; 31 36 2E 37 0D 0A 43 6F&amp;nbsp; 6E 6E 65 63 74 69 6F 6E&amp;nbsp; 16.7..Connection&lt;BR /&gt;0000F0&amp;nbsp; 3A 20 4B 65 65 70 2D 41&amp;nbsp; 6C 69 76 65 0D 0A 0D 0A&amp;nbsp; : Keep-Alive....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some alerts also warrant a larger capture for example web attacks to correctly false positive the traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be gratfeully received.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BTW can I view IPS events from the CLI on the unit?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:52:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-decodes-in-alerts/m-p/1408999#M68114</guid>
      <dc:creator>markidotw</dc:creator>
      <dc:date>2019-03-10T11:52:08Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Decodes in Alerts</title>
      <link>https://community.cisco.com/t5/network-security/packet-decodes-in-alerts/m-p/1409000#M68116</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are two types of packet captures on the IPS Sensors. The one you may be looking at&lt;/P&gt;&lt;P&gt;is included in the alert. This is set by selecting the "produce-verbose-alert" option on the associated signature. There are no further options for this method of packet capture.&lt;/P&gt;&lt;P&gt;The second way of performing packet captures are is the "log-attacter-packets" and "log-victim-packets" (select these as a pair). They will create a PCAP file on the sensor with X number of packets captured. X is settable on a global basis for all signature captures (not on a sig by sig basis).&lt;/P&gt;&lt;P&gt;You can see alerts no the CLI with these commands:&lt;/P&gt;&lt;P&gt;show events alert past 01:00 (to see alerts for the past hour + current alerts as they roll in)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jan 2010 17:07:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-decodes-in-alerts/m-p/1409000#M68116</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2010-01-21T17:07:29Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Decodes in Alerts</title>
      <link>https://community.cisco.com/t5/network-security/packet-decodes-in-alerts/m-p/1409001#M68117</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bob,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's really helped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Jan 2010 10:12:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-decodes-in-alerts/m-p/1409001#M68117</guid>
      <dc:creator>markidotw</dc:creator>
      <dc:date>2010-01-25T10:12:42Z</dc:date>
    </item>
  </channel>
</rss>

