<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Security Monitor 2.1 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/security-monitor-2-1/m-p/435610#M95454</link>
    <description>&lt;P&gt;Folks,&lt;/P&gt;&lt;P&gt;         I have a couple of questions regarding IDS MC 2.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Will it generate reports giving information about lets say critical alarms or lets say informational alarms?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) How often does it access the database. I mean lets say the attck was happening, how soon would the security monitor be able to send an e-mail about that??&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 09:36:44 GMT</pubDate>
    <dc:creator>NAVIN PARWAL</dc:creator>
    <dc:date>2019-03-10T09:36:44Z</dc:date>
    <item>
      <title>Security Monitor 2.1</title>
      <link>https://community.cisco.com/t5/network-security/security-monitor-2-1/m-p/435610#M95454</link>
      <description>&lt;P&gt;Folks,&lt;/P&gt;&lt;P&gt;         I have a couple of questions regarding IDS MC 2.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Will it generate reports giving information about lets say critical alarms or lets say informational alarms?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) How often does it access the database. I mean lets say the attck was happening, how soon would the security monitor be able to send an e-mail about that??&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:36:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-monitor-2-1/m-p/435610#M95454</guid>
      <dc:creator>NAVIN PARWAL</dc:creator>
      <dc:date>2019-03-10T09:36:44Z</dc:date>
    </item>
    <item>
      <title>Re: Security Monitor 2.1</title>
      <link>https://community.cisco.com/t5/network-security/security-monitor-2-1/m-p/435611#M95463</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Use SecMon with MC2.1. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It will report severity as described in question #1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as #2, secmon in MC2.1 will "subscribe" to a sensor and the events are "more or less" real time. This means that once a subscrition is established the IPS appliance will send the event as it is generated. However keep in mind that if the IPS box is busy, attack interrupts take precendnce over event reporting. Bottom line is that events should be in secmon within 10-20 second of when they fired.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Aug 2005 18:34:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-monitor-2-1/m-p/435611#M95463</guid>
      <dc:creator>gabelar</dc:creator>
      <dc:date>2005-08-29T18:34:00Z</dc:date>
    </item>
  </channel>
</rss>

