<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Event retrieval  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/event-retrieval/m-p/1346067#M76851</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply. &lt;/P&gt;&lt;P&gt;i tried receiving events with an CA`s snmp receiver but the events i m receiving are not readable .. &lt;/P&gt;&lt;P&gt;can u sugggests any receiver.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 28 Jun 2009 08:16:35 GMT</pubDate>
    <dc:creator>manmeetshergill</dc:creator>
    <dc:date>2009-06-28T08:16:35Z</dc:date>
    <item>
      <title>Event retrieval</title>
      <link>https://community.cisco.com/t5/network-security/event-retrieval/m-p/1346065#M76849</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;i am running a network having 30 IPS (which indcludes SSM20s, IDSMs and IPS 44XX).&lt;/P&gt;&lt;P&gt;i dont have mars device. Is there any way to retrieve events from all the IPS to one central location using csmanager ??&lt;/P&gt;&lt;P&gt;or is there any freeware that can do the job. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:40:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/event-retrieval/m-p/1346065#M76849</guid>
      <dc:creator>manmeetshergill</dc:creator>
      <dc:date>2019-03-10T11:40:51Z</dc:date>
    </item>
    <item>
      <title>Re: Event retrieval</title>
      <link>https://community.cisco.com/t5/network-security/event-retrieval/m-p/1346066#M76850</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;CSM doesn't collect events, it can only be used to manage the signatures and configurations on your sensors. To collect events you'll need a SIM like MARS, NetForenisics, Intelitactics that has an SDEE (version 7.x has a newer protocol that is backards compatible with SDEE, I forget it's name) listener.&lt;/P&gt;&lt;P&gt;There were some open source pieces you could try to put together yourself, but nothing I know of that is preassembled.&lt;/P&gt;&lt;P&gt;Alternately, you could option all your enabled signatures to fire off an SNMP trap and collect those with a free SNMP receiver. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Jun 2009 14:12:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/event-retrieval/m-p/1346066#M76850</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2009-06-26T14:12:45Z</dc:date>
    </item>
    <item>
      <title>Re: Event retrieval</title>
      <link>https://community.cisco.com/t5/network-security/event-retrieval/m-p/1346067#M76851</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply. &lt;/P&gt;&lt;P&gt;i tried receiving events with an CA`s snmp receiver but the events i m receiving are not readable .. &lt;/P&gt;&lt;P&gt;can u sugggests any receiver.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 28 Jun 2009 08:16:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/event-retrieval/m-p/1346067#M76851</guid>
      <dc:creator>manmeetshergill</dc:creator>
      <dc:date>2009-06-28T08:16:35Z</dc:date>
    </item>
    <item>
      <title>Re: Event retrieval</title>
      <link>https://community.cisco.com/t5/network-security/event-retrieval/m-p/1346068#M76852</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You may use OpenNMS as free traps receiver.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Oct 2009 11:40:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/event-retrieval/m-p/1346068#M76852</guid>
      <dc:creator>andrey.dugin</dc:creator>
      <dc:date>2009-10-19T11:40:06Z</dc:date>
    </item>
  </channel>
</rss>

