cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
592
Views
0
Helpful
1
Replies

IDS 4215 IP logging

jmayes
Level 1
Level 1

The IDS MC and Cisco's IDS book show configuration for IP packet capture for later viewing through Ethereal.

Question: If I set IP logging on the IDS, how do I retrieve the file for Ethereal analysis?

1 Reply 1

marcabal
Cisco Employee
Cisco Employee

There are 2 (and possibly 3) ways for retreiving the IP Log file from the sensor.

1) From the CLI

You can use the "iplog-status" command in the sensor's CLI to view the status of the IP Logs and determine the iplog id of the log you are interested in.

You can then use the "copy iplog <ftp://user@host/directory/filename>" to copy that IP Log to an ftp server than you can then access to copy the log to your desktop to run ethereal on.

2) From IDM

Optionally you can view the list of IP Logs within IDM. Within IDM you can then download the IP Log directly to your desktop.

3) From another monitoring tool

I have heard that some monitoring tools are now offering a new menu option for downloading the IP Log from the sensor. I am not sure in which monitoring tools this menu option has been implemented.

Review Cisco Networking for a $25 gift card