<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Doubt in IPS log in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/doubt-in-ips-log/m-p/764215#M86366</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The 192.x.x.x is the IP address of the device sending this syslog, most likely the IOS IPS router.&lt;/P&gt;&lt;P&gt;SEV: 75 Must be a new numerical way of desrcibing severity, what version of IOS are you running, &amp;gt;12.4.6T?&lt;/P&gt;&lt;P&gt;The 4 in %IPS-4 is the syslog level, 4 is the Warning level &lt;A class="jive-link-custom" href="http://www.routergod.com/agentsmith/" target="_blank"&gt;http://www.routergod.com/agentsmith/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;RiskRating is a Cisco thing (you really didn't search CCO much before porting your questions, did you?)&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://cisco.com/en/US/products/hw/vpndevc/ps4077/products_white_paper0900aecd80191021.shtml" target="_blank"&gt;http://cisco.com/en/US/products/hw/vpndevc/ps4077/products_white_paper0900aecd80191021.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 22 Jun 2007 16:36:20 GMT</pubDate>
    <dc:creator>rhermes</dc:creator>
    <dc:date>2007-06-22T16:36:20Z</dc:date>
    <item>
      <title>Doubt in IPS log</title>
      <link>https://community.cisco.com/t5/network-security/doubt-in-ips-log/m-p/764214#M86365</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to develop a script which will list events based on certain conditions. For this i need to know about all the attributes in the logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is a sample log,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;05-12-2007  23:57:28    192.x.x.x local7.warn 2069294: 2080360: May 12 2007 23:56:48.813 CDT: %IPS-4-SIGNATURE: Sig:3109 Subsig:0 Sev:75  [&amp;lt;SRC IP&amp;gt;:&amp;lt;SRC_PORT&amp;gt; -&amp;gt; &amp;lt;Destination IP&amp;gt;:&amp;lt;DST_PORT&amp;gt;] RiskRating:56&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following are the attributes which i am unable to determine,&lt;/P&gt;&lt;P&gt;192.x.x.x - ip of the device ? &lt;/P&gt;&lt;P&gt;SEV:75 - severity ? then what is "4" in %IPS-4 ? what is the range for this ?&lt;/P&gt;&lt;P&gt;what is RiskRating:56 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanx in advance.&lt;/P&gt;&lt;P&gt;-S-&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:40:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/doubt-in-ips-log/m-p/764214#M86365</guid>
      <dc:creator>linker.team</dc:creator>
      <dc:date>2019-03-10T10:40:07Z</dc:date>
    </item>
    <item>
      <title>Re: Doubt in IPS log</title>
      <link>https://community.cisco.com/t5/network-security/doubt-in-ips-log/m-p/764215#M86366</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The 192.x.x.x is the IP address of the device sending this syslog, most likely the IOS IPS router.&lt;/P&gt;&lt;P&gt;SEV: 75 Must be a new numerical way of desrcibing severity, what version of IOS are you running, &amp;gt;12.4.6T?&lt;/P&gt;&lt;P&gt;The 4 in %IPS-4 is the syslog level, 4 is the Warning level &lt;A class="jive-link-custom" href="http://www.routergod.com/agentsmith/" target="_blank"&gt;http://www.routergod.com/agentsmith/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;RiskRating is a Cisco thing (you really didn't search CCO much before porting your questions, did you?)&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://cisco.com/en/US/products/hw/vpndevc/ps4077/products_white_paper0900aecd80191021.shtml" target="_blank"&gt;http://cisco.com/en/US/products/hw/vpndevc/ps4077/products_white_paper0900aecd80191021.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jun 2007 16:36:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/doubt-in-ips-log/m-p/764215#M86366</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2007-06-22T16:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: Doubt in IPS log</title>
      <link>https://community.cisco.com/t5/network-security/doubt-in-ips-log/m-p/764216#M86367</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thx for the reply. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jun 2007 13:49:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/doubt-in-ips-log/m-p/764216#M86367</guid>
      <dc:creator>linker.team</dc:creator>
      <dc:date>2007-06-26T13:49:06Z</dc:date>
    </item>
  </channel>
</rss>

