<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Reporting and Alert Querying  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/reporting-and-alert-querying/m-p/872986#M84881</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was afraid of that. Even though I'm looking into MARS I hate to have my decision tied to improving the functionality of a product I already have.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 24 Jan 2008 15:56:41 GMT</pubDate>
    <dc:creator>rolandshum</dc:creator>
    <dc:date>2008-01-24T15:56:41Z</dc:date>
    <item>
      <title>Reporting and Alert Querying</title>
      <link>https://community.cisco.com/t5/network-security/reporting-and-alert-querying/m-p/872984#M84879</link>
      <description>&lt;P&gt;I'm just getting started with my IDS/IPS SSM-20 module. I'm looking for some reporting and querying capabilities for it. Is there a function or ability within the IDM 5.1 application or even if I upgrade. Is possible to look for all alerts for a particular IP address or a specified signature? Can I generate a report on how many attacks were mitigated?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:56:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reporting-and-alert-querying/m-p/872984#M84879</guid>
      <dc:creator>rolandshum</dc:creator>
      <dc:date>2019-03-10T10:56:53Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting and Alert Querying</title>
      <link>https://community.cisco.com/t5/network-security/reporting-and-alert-querying/m-p/872985#M84880</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Both IDM and "show events alert" have very basic querying capabilities. The only thing you can do is to mark some signature with "traits" code and show alerts fired by this signature with:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sensor# sh events alert include-traits ?&lt;/P&gt;&lt;P&gt;&amp;lt;0-15&amp;gt;     Traits to include in the show events output.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try IDS Event Viewer. IEV is a free tool that can be downloaded from the Cisco website. But is very limited too. The primary Cisco product for viewing/reporting is the Cisco MARS. But it is expensive...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Jan 2008 14:00:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reporting-and-alert-querying/m-p/872985#M84880</guid>
      <dc:creator>ovt</dc:creator>
      <dc:date>2008-01-24T14:00:06Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting and Alert Querying</title>
      <link>https://community.cisco.com/t5/network-security/reporting-and-alert-querying/m-p/872986#M84881</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was afraid of that. Even though I'm looking into MARS I hate to have my decision tied to improving the functionality of a product I already have.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Jan 2008 15:56:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reporting-and-alert-querying/m-p/872986#M84881</guid>
      <dc:creator>rolandshum</dc:creator>
      <dc:date>2008-01-24T15:56:41Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting and Alert Querying</title>
      <link>https://community.cisco.com/t5/network-security/reporting-and-alert-querying/m-p/872987#M84882</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can refer this guide for more information on IDS&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps4077/products_tech_note09186a008053183f.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps4077/products_tech_note09186a008053183f.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Jan 2008 19:20:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reporting-and-alert-querying/m-p/872987#M84882</guid>
      <dc:creator>bwilmoth</dc:creator>
      <dc:date>2008-01-24T19:20:04Z</dc:date>
    </item>
  </channel>
</rss>

