<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS-SM Archive Pruning File format in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-sm-archive-pruning-file-format/m-p/490602#M98820</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Pruning archive files are CSV text files. They can contain the following types of data: &lt;/P&gt;&lt;P&gt;NIDS (Network IDS events) &lt;/P&gt;&lt;P&gt;Firewall (PIX Firewall and Firewall Service Module events) &lt;/P&gt;&lt;P&gt;CSA (CSA Host IDS events &lt;/P&gt;&lt;P&gt;Audit log (System events) &lt;/P&gt;&lt;P&gt;You can import audit log files upgraded from the Security Monitor 1.2 database. However, in Security Monitor 2.0 or later, you can no longer archive audit log data. &lt;/P&gt;&lt;P&gt;Pruning archive files are created by the Pruning Daemon (IDS_DatabasePrune) &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/cscowork/ps3991/products_user_guide_chapter09186a008059f484.html#wp220602" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/cscowork/ps3991/products_user_guide_chapter09186a008059f484.html#wp220602&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 31 Jan 2006 22:09:13 GMT</pubDate>
    <dc:creator>pradeepde</dc:creator>
    <dc:date>2006-01-31T22:09:13Z</dc:date>
    <item>
      <title>IPS-SM Archive Pruning File format</title>
      <link>https://community.cisco.com/t5/network-security/ips-sm-archive-pruning-file-format/m-p/490601#M98815</link>
      <description>&lt;P&gt;The Archived Pruning files from the VMS Event database contain &lt;/P&gt;&lt;P&gt;the alerts that are pruned to keep the database a reasonable size. Each time    &lt;/P&gt;&lt;P&gt;pruning occurs a new directory is created, named after the date/time of         &lt;/P&gt;&lt;P&gt;creation such as:&lt;/P&gt;&lt;P&gt;01012006_061416&lt;/P&gt;&lt;P&gt;Within each created directory are 6 files&lt;/P&gt;&lt;P&gt;nids_2-0_01012006_061416.txt&lt;/P&gt;&lt;P&gt;nidsAttack_2-0_01012006_061416.txt&lt;/P&gt;&lt;P&gt;nidsAvp_2-0_01012006_061416.txt&lt;/P&gt;&lt;P&gt;nidsEventLog_2-0_01012006_061416.txt&lt;/P&gt;&lt;P&gt;nidsIp_2-0_01012006_061416.txt&lt;/P&gt;&lt;P&gt;nidsTrigger_2-0_01012006_061416.txt&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The contents of these .txt files are in Comma Separated Value format. I need    &lt;/P&gt;&lt;P&gt;the name and definition of the columns and files, but can't find any documentation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:51:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-sm-archive-pruning-file-format/m-p/490601#M98815</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2019-03-10T09:51:47Z</dc:date>
    </item>
    <item>
      <title>Re: IPS-SM Archive Pruning File format</title>
      <link>https://community.cisco.com/t5/network-security/ips-sm-archive-pruning-file-format/m-p/490602#M98820</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Pruning archive files are CSV text files. They can contain the following types of data: &lt;/P&gt;&lt;P&gt;NIDS (Network IDS events) &lt;/P&gt;&lt;P&gt;Firewall (PIX Firewall and Firewall Service Module events) &lt;/P&gt;&lt;P&gt;CSA (CSA Host IDS events &lt;/P&gt;&lt;P&gt;Audit log (System events) &lt;/P&gt;&lt;P&gt;You can import audit log files upgraded from the Security Monitor 1.2 database. However, in Security Monitor 2.0 or later, you can no longer archive audit log data. &lt;/P&gt;&lt;P&gt;Pruning archive files are created by the Pruning Daemon (IDS_DatabasePrune) &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/cscowork/ps3991/products_user_guide_chapter09186a008059f484.html#wp220602" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/cscowork/ps3991/products_user_guide_chapter09186a008059f484.html#wp220602&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Jan 2006 22:09:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-sm-archive-pruning-file-format/m-p/490602#M98820</guid>
      <dc:creator>pradeepde</dc:creator>
      <dc:date>2006-01-31T22:09:13Z</dc:date>
    </item>
  </channel>
</rss>

