cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
295
Views
0
Helpful
0
Replies

cisco reference client (perl based client) | estreamer FMC testing

harsh_tw
Level 1
Level 1

HEllo All,
I am using cisco reference client (perl based client) . The connection is good. No errors.
But I am facing below issues:
I am using following command to pull the IDS events with signature ID, generator ID but I am not getting any events with specified signature ID.
./ssl_test.pl -v -pk <IP>.pkcs12 -pa password <FMC server IP> -s all -o print -f print-fmc.txt -s all -r <signature/rule ID, generator ID>

  1. Ideally we should receive events with signature ID = specified signature ID right ?
  2. Ideally we should receive IDS events with specified condition right ?
  3. How can I make sure the perl based client pulls all INTRUSION type events ?
  4. What FLAGs I need to use ? and where can I store them in perl modules to be used by ssl_test.pl script ?
  5. Which property of events is compared with the bookmark value set ?
0 Replies 0