<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User accounting in IPS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/user-accounting-in-ips/m-p/785946#M85805</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From the CLI:&lt;/P&gt;&lt;P&gt;# show event status past 23:59 | include loginAction&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure how you'd go back farther without using the IDM (in the IDM you can tell it to show entire log buffer).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 07 Sep 2007 21:30:17 GMT</pubDate>
    <dc:creator>mhellman</dc:creator>
    <dc:date>2007-09-07T21:30:17Z</dc:date>
    <item>
      <title>User accounting in IPS</title>
      <link>https://community.cisco.com/t5/network-security/user-accounting-in-ips/m-p/785944#M85803</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way that one can see who and when has logged into the IPS device for a given period of time?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:46:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-accounting-in-ips/m-p/785944#M85803</guid>
      <dc:creator>rnaydenov</dc:creator>
      <dc:date>2019-03-10T10:46:39Z</dc:date>
    </item>
    <item>
      <title>Re: User accounting in IPS</title>
      <link>https://community.cisco.com/t5/network-security/user-accounting-in-ips/m-p/785945#M85804</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The IPS device maintains a log of all events (including who has logged). However if there are lot of events happening the entries in the log gets replaced fast. You can see this log using command "show log" on the IPS device. The IPS cannot be used with Radius or TACACS for authentication or authorization.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Sep 2007 17:08:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-accounting-in-ips/m-p/785945#M85804</guid>
      <dc:creator>amritpatek</dc:creator>
      <dc:date>2007-09-07T17:08:45Z</dc:date>
    </item>
    <item>
      <title>Re: User accounting in IPS</title>
      <link>https://community.cisco.com/t5/network-security/user-accounting-in-ips/m-p/785946#M85805</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From the CLI:&lt;/P&gt;&lt;P&gt;# show event status past 23:59 | include loginAction&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure how you'd go back farther without using the IDM (in the IDM you can tell it to show entire log buffer).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Sep 2007 21:30:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-accounting-in-ips/m-p/785946#M85805</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2007-09-07T21:30:17Z</dc:date>
    </item>
  </channel>
</rss>

