cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
591
Views
0
Helpful
1
Replies

Cisco IPS log monitoring

shalendra2
Level 1
Level 1

Hi Team,

               We have a device Cisco IPS 4260-k9. We want to forward syslog events to external syslog server. Please specify

the steps. and also provide the difference, If we use SDEE.

 

Regards,

Shalendra

1 Reply 1

Marvin Rhoads
Hall of Fame
Hall of Fame

Syslog events (UDP-based messages) from a Cisco IPS appliance are only high level system status messages (server up, signature update applied etc.).

Actual intrusion events are only exported via the more reliable tcp-based SDEE. For that you use a client such as Cisco IPS Manager Express (for small deployments) or Cisco Security Manager (enterprise class tool).

Review Cisco Networking for a $25 gift card