cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
333
Views
0
Helpful
1
Replies

IDS old entries logs

ahpark78
Level 1
Level 1

Hi,

I am trying to check back old packets sniffed on 10,11 May 2006 but I do not know where to go to get the old archive logs.

The reason is, the Firewall on another site detected there are 2 PCs trying to scan the whole range of IP addresses. So I am using IDS to check those source entries,packets..

Need your assistance.

thanks..

1 Reply 1

vkapoor5
Level 5
Level 5

If you are using IEV, you use the "Data Source" option to view the old alrams.

http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids10/idmiev/swchap6.htm#wp604788

You can specify the dates here.

Review Cisco Networking for a $25 gift card