<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IDS Sensor 4.1 doesn't capture events. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ids-sensor-4-1-doesn-t-capture-events/m-p/452071#M97934</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;remove 4.1.4g fetch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 21 Jun 2005 03:29:47 GMT</pubDate>
    <dc:creator>chulje.sung</dc:creator>
    <dc:date>2005-06-21T03:29:47Z</dc:date>
    <item>
      <title>IDS Sensor 4.1 doesn't capture events.</title>
      <link>https://community.cisco.com/t5/network-security/ids-sensor-4-1-doesn-t-capture-events/m-p/452068#M97930</link>
      <description>&lt;P&gt;My IDS Sensor 4.1 stops capturing events after some time. I don't know if maybe it is because there are a lot of VLANs in SPAN and the IDS doesn't support all this traffic. Am i wrong?&lt;/P&gt;&lt;P&gt;Here is the show ver output:&amp;gt;&lt;/P&gt;&lt;P&gt;# sh ver&lt;/P&gt;&lt;P&gt;Application Partition:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Systems Intrusion Detection Sensor, Version 4.1(4)S174&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OS Version 2.4.18-5-phoenix&lt;/P&gt;&lt;P&gt;Platform: WS-SVC-IDSM2-BUN&lt;/P&gt;&lt;P&gt;Sensor up-time is 20:49.&lt;/P&gt;&lt;P&gt;Using 337403904 out of 1979682816 bytes of available memory (17% usage)&lt;/P&gt;&lt;P&gt;Using 2.0G out of 17G bytes of available disk space (13% usage)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MainApp             2005_Feb_15_10.32   (Eng4g)     2005-02-15T10:35:34-0600   Running   &lt;/P&gt;&lt;P&gt;AnalysisEngine      2005_Feb_15_10.32   (Eng4g)     2005-02-15T10:35:34-0600   Running   &lt;/P&gt;&lt;P&gt;Authentication      2005_Feb_15_10.32   (Eng4g)     2005-02-15T10:35:34-0600   Running   &lt;/P&gt;&lt;P&gt;Logger              2005_Feb_15_10.32   (Eng4g)     2005-02-15T10:35:34-0600   Running   &lt;/P&gt;&lt;P&gt;NetworkAccess       2005_Feb_15_10.32   (Eng4g)     2005-02-15T10:35:34-0600   Running   &lt;/P&gt;&lt;P&gt;TransactionSource   2005_Feb_15_10.32   (Eng4g)     2005-02-15T10:35:34-0600   Running   &lt;/P&gt;&lt;P&gt;WebServer           2005_Feb_15_10.32   (Eng4g)     2005-02-15T10:35:34-0600   Running   &lt;/P&gt;&lt;P&gt;CLI                 2004_Apr_15_15.03   (Release)   2004-04-15T15:11:59-0500             &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Upgrade History:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;* IDS-sig-4.1-4-S172           08:51:06 UTC Wed Jun 01 2005   &lt;/P&gt;&lt;P&gt;  IDS-sig-4.1-4-S174.rpm.pkg   15:13:12 UTC Wed Jun 08 2005   &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maintenance Partition Version 2.1(1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And here is the "sh event" output:&lt;/P&gt;&lt;P&gt;# sh event&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;evError: eventId=1099377235773324837 severity=warning &lt;/P&gt;&lt;P&gt;  originator: &lt;/P&gt;&lt;P&gt;    hostId: CISCO-IDS&lt;/P&gt;&lt;P&gt;    appName: sensorApp&lt;/P&gt;&lt;P&gt;    appInstanceId: 1206&lt;/P&gt;&lt;P&gt;  time: 2005/06/10 08:43:21 2005/06/10 10:43:21 GMT&lt;/P&gt;&lt;P&gt;  errorMessage: name=errWarning Producer appears to be out of superblocks...consider configuring TCPReassemblyMode to loose FreeBlocks: 2155&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;evError: eventId=1099377235773324838 severity=warning &lt;/P&gt;&lt;P&gt;  originator: &lt;/P&gt;&lt;P&gt;    hostId: CISCO-IDS&lt;/P&gt;&lt;P&gt;    appName: sensorApp&lt;/P&gt;&lt;P&gt;    appInstanceId: 1206&lt;/P&gt;&lt;P&gt;  time: 2005/06/10 08:43:23 2005/06/10 10:43:23 GMT&lt;/P&gt;&lt;P&gt;  errorMessage: name=errWarning Producer appears to be out of superblocks...consider configuring TCPReassemblyMode to loose FreeBlocks: 2155&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But i have already configured TCP Reassembly Mode to 'loose' and it does the same: after some time, it logs a few events and starts logging this event, but the Security Monitor stops showing me any Alarm. What can I do to solve this?&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:29:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-sensor-4-1-doesn-t-capture-events/m-p/452068#M97930</guid>
      <dc:creator>jpoudereux</dc:creator>
      <dc:date>2019-03-10T09:29:32Z</dc:date>
    </item>
    <item>
      <title>Re: IDS Sensor 4.1 doesn't capture events.</title>
      <link>https://community.cisco.com/t5/network-security/ids-sensor-4-1-doesn-t-capture-events/m-p/452069#M97932</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When the IDSM2 starts crashing (i mean, logging only this event), i clear the IDSM2 interface counters and i realize that no packet are processed and the "missed packet percentage" grows and grows. &lt;/P&gt;&lt;P&gt;That means after this crashing it stops processing packets and loses every traffic it receives. The question is why? And how can i solve this?&lt;/P&gt;&lt;P&gt;Thanks everybody.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Jun 2005 10:26:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-sensor-4-1-doesn-t-capture-events/m-p/452069#M97932</guid>
      <dc:creator>jpoudereux</dc:creator>
      <dc:date>2005-06-10T10:26:21Z</dc:date>
    </item>
    <item>
      <title>Re: IDS Sensor 4.1 doesn't capture events.</title>
      <link>https://community.cisco.com/t5/network-security/ids-sensor-4-1-doesn-t-capture-events/m-p/452070#M97933</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The solution to this problem I was having is to install Maintenance Partition Image 2.1(2). &lt;/P&gt;&lt;P&gt;It works!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Jun 2005 14:32:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-sensor-4-1-doesn-t-capture-events/m-p/452070#M97933</guid>
      <dc:creator>jpoudereux</dc:creator>
      <dc:date>2005-06-15T14:32:04Z</dc:date>
    </item>
    <item>
      <title>Re: IDS Sensor 4.1 doesn't capture events.</title>
      <link>https://community.cisco.com/t5/network-security/ids-sensor-4-1-doesn-t-capture-events/m-p/452071#M97934</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;remove 4.1.4g fetch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2005 03:29:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-sensor-4-1-doesn-t-capture-events/m-p/452071#M97934</guid>
      <dc:creator>chulje.sung</dc:creator>
      <dc:date>2005-06-21T03:29:47Z</dc:date>
    </item>
  </channel>
</rss>

