<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AIP-SSM20 Event Store in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/aip-ssm20-event-store/m-p/1063304#M78751</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is also the IEV successor called Cisco IME (IPS Manager Express), which can manage up to 5 IPS devices and also can pull and store events.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/cgi-bin/tablebuild.pl/ips-ime" target="_blank"&gt;http://www.cisco.com/cgi-bin/tablebuild.pl/ips-ime&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 28 Sep 2008 17:25:01 GMT</pubDate>
    <dc:creator>mathias.mahnke</dc:creator>
    <dc:date>2008-09-28T17:25:01Z</dc:date>
    <item>
      <title>AIP-SSM20 Event Store</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm20-event-store/m-p/1063301#M78748</link>
      <description>&lt;P&gt;Anyone know is there a way to retrieve/backup the events in the AIP-SSM20 event store ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had read through their manual/white paper, but it didn't mention anything about retrieving/backing up the event store except on how to clear it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CMYip&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:18:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm20-event-store/m-p/1063301#M78748</guid>
      <dc:creator>cmyip</dc:creator>
      <dc:date>2019-03-10T11:18:27Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM20 Event Store</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm20-event-store/m-p/1063302#M78749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The IDS Sensor can not archive the signature events for a long time as they have a fixed memory space in order to store the signature events, which is overwritten when full. But, these events can be stored to an external management system such as CiscoWorks VPN/Security Management Solution (VMS), Cisco Security Monitoring, Analysis and Response System (CS-MARS), or IDS Event Viewer (IEV). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Refer to Cisco Downloads in order to download the IDS Event Viewer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sushil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Sep 2008 12:36:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm20-event-store/m-p/1063302#M78749</guid>
      <dc:creator>suschoud</dc:creator>
      <dc:date>2008-09-26T12:36:10Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM20 Event Store</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm20-event-store/m-p/1063303#M78750</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;suscoud is right. Cisco has shrunk the event store as they have moved from hard disk based sensors to flash based with less storage. You have to get your events off the sensor or you will loose them. In addition to the methods suscoud mentioned above you also use SNMP if you set the action on each active signature you want to alert to send an SNMP Trap when they fire. This does not send as much information as an SDEE feed to VMS/CS-MARS/IEV.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Sep 2008 16:23:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm20-event-store/m-p/1063303#M78750</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2008-09-26T16:23:31Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM20 Event Store</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm20-event-store/m-p/1063304#M78751</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is also the IEV successor called Cisco IME (IPS Manager Express), which can manage up to 5 IPS devices and also can pull and store events.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/cgi-bin/tablebuild.pl/ips-ime" target="_blank"&gt;http://www.cisco.com/cgi-bin/tablebuild.pl/ips-ime&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 28 Sep 2008 17:25:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm20-event-store/m-p/1063304#M78751</guid>
      <dc:creator>mathias.mahnke</dc:creator>
      <dc:date>2008-09-28T17:25:01Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM20 Event Store</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm20-event-store/m-p/1063305#M78752</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for all the reply. I'm using the IME now, but i don't see any option saving the store events to hard disk.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will try out the IDS Event Viewer later. I read that it had a archive feature that can store the event to hard disk.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will let you guy know the result later.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CMYip&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Sep 2008 08:24:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm20-event-store/m-p/1063305#M78752</guid>
      <dc:creator>cmyip</dc:creator>
      <dc:date>2008-09-30T08:24:47Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM20 Event Store</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm20-event-store/m-p/1063306#M78753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does anyone know how to retrieve the archived data? I upgraded from IEV to IME but need to track down the old data for a PCI audit. Any help will be greatly appreciated. Thanks. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Oct 2008 18:52:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm20-event-store/m-p/1063306#M78753</guid>
      <dc:creator>vpersaud001</dc:creator>
      <dc:date>2008-10-24T18:52:50Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM20 Event Store</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm20-event-store/m-p/1063307#M78754</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Anyone?? Thanks. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Oct 2008 20:09:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm20-event-store/m-p/1063307#M78754</guid>
      <dc:creator>vpersaud001</dc:creator>
      <dc:date>2008-10-27T20:09:18Z</dc:date>
    </item>
  </channel>
</rss>

