<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IDSM2 logging in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/idsm2-logging/m-p/1341846#M68242</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you can use mars or IME (any combination) to both simultaneously pull alerts using sdee from the sensor.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 20 Nov 2009 23:43:07 GMT</pubDate>
    <dc:creator>Jim Thomas</dc:creator>
    <dc:date>2009-11-20T23:43:07Z</dc:date>
    <item>
      <title>IDSM2 logging</title>
      <link>https://community.cisco.com/t5/network-security/idsm2-logging/m-p/1341845#M68241</link>
      <description>&lt;P&gt;Is it possible to send events from the IDSM2 to two different aggregation points simultaniously?&amp;nbsp; Say for instance, Cisco MARS and some other SIEM.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:49:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm2-logging/m-p/1341845#M68241</guid>
      <dc:creator>000000jbl</dc:creator>
      <dc:date>2019-03-10T11:49:58Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM2 logging</title>
      <link>https://community.cisco.com/t5/network-security/idsm2-logging/m-p/1341846#M68242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you can use mars or IME (any combination) to both simultaneously pull alerts using sdee from the sensor.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Nov 2009 23:43:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm2-logging/m-p/1341846#M68242</guid>
      <dc:creator>Jim Thomas</dc:creator>
      <dc:date>2009-11-20T23:43:07Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM2 logging</title>
      <link>https://community.cisco.com/t5/network-security/idsm2-logging/m-p/1341847#M68243</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;MARS and IME both use the 'pull' event architecture to retrive events from IPS devices, and as already answered both can 'pull' events from the same IPS device simultaneously without any issues (except the performance lag). IME will store events in its MSDE database and MARS has its own oracle database (which can be archived using unix NFS). IME is limited to 10 sensors tough.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Nov 2009 14:00:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm2-logging/m-p/1341847#M68243</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2009-11-22T14:00:09Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM2 logging</title>
      <link>https://community.cisco.com/t5/network-security/idsm2-logging/m-p/1341848#M68245</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, so do I understand correctly that there is no way to have IDSM send its logs out to a generic log server?&amp;nbsp; I undersatd SDEE and the "pulling" of events from IDSM.&amp;nbsp; Is there no way to have IDSM push?&amp;nbsp; Maybe via syslog rather than SDEE?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Nov 2009 16:02:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm2-logging/m-p/1341848#M68245</guid>
      <dc:creator>000000jbl</dc:creator>
      <dc:date>2009-11-24T16:02:29Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM2 logging</title>
      <link>https://community.cisco.com/t5/network-security/idsm2-logging/m-p/1341849#M68247</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are correct, the IPS does not support syslog reporting. You can enable SNMP traps on a per signature basis tough. But once has to be careful not to over whelm the IPS Cpu/memory resources in doing so.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Nov 2009 20:55:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm2-logging/m-p/1341849#M68247</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2009-11-24T20:55:10Z</dc:date>
    </item>
  </channel>
</rss>

