cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
926
Views
0
Helpful
1
Replies

Help with IME 7.1 and store events

Hello,

I have a trouble with an IPS 4270, I have configured the IPS in inline mode with policy action sg0 with log all permit (packet, atack, victim). I wan to store the events in the external server or I want to see in the IME 7.1, but I can not see this events. How i can configure the IME to i see this events and generate reports. I have seen in Cisco Guide, but I havent understand.

Sorry form y english.

Regards,

Álvaro

1 Reply 1

Dustin Ralich
Cisco Employee
Cisco Employee

Hello Alvaro.

I have configured the IPS in inline mode with policy action sg0 with log all permit (packet, atack, victim).

If you mean you have configured an EAO (Event Action Override) set to add the Log Attacker Packets, Log Victim Packets, and Log Pair Packets Actions: This will almost certainly result in your sensor becoming oversubscribed, unresponsive, etc. Please review the section of this document regarding this.

I want to see in the IME 7.1, but I can not see this events. How i can configure the IME to i see this events

You can download copies of the IP Log file(s) present on the sensor from within IME from the Configuration tab > Sensor Monitoring > Time-Based Actions > IP Logging section. Each IP Log file has an associated "Alert ID" that corresponds with the event/Alert that generated it.

The Alerts themselves can be reviewed via IME's Event Monitoring tab.

Review Cisco Networking for a $25 gift card