09-29-2009 06:57 AM - edited 03-10-2019 04:46 AM
Hi, we have IDSM-2 installed in cat 6500 system. Anyone knows how to get IDSM-2 syslog file? and how to config it to send log to syslog server? I know these two questions are pretty simple, but I have not found answers yet.
Any help would be greatly appreciated.
Solved! Go to Solution.
09-29-2009 11:27 PM
U can get events from IDSM in SDEE format. Use IPS Manager or another tool to collect these logs.
09-30-2009 08:26 AM
To expand on what tsippa said, the Cisco IPS sensors do not have a syslog output. the standard way to get events off the sensor is via an SDEE feed. You can also set each signature to issue an SNMP trap when they fire, but this must be done on a signature by signature basis.
10-16-2009 06:00 AM
Using traps is possible, but per-signature basis is not one way. You may use event action overrides to activate traps on all signatures or according to risk rating.
09-29-2009 11:27 PM
U can get events from IDSM in SDEE format. Use IPS Manager or another tool to collect these logs.
09-30-2009 08:26 AM
To expand on what tsippa said, the Cisco IPS sensors do not have a syslog output. the standard way to get events off the sensor is via an SDEE feed. You can also set each signature to issue an SNMP trap when they fire, but this must be done on a signature by signature basis.
10-16-2009 06:00 AM
Using traps is possible, but per-signature basis is not one way. You may use event action overrides to activate traps on all signatures or according to risk rating.
10-20-2009 05:10 AM
Thanks a lot for all of the great help.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide