09-13-2011 04:52 PM - edited 03-10-2019 05:28 AM
This may be a very naive question, if so it will certainly match my knowledge level! Can log messages be sent to a Kiwi Syslog Server? If so, how to configure?
Many thanx
-michael
Solved! Go to Solution.
09-14-2011 08:24 AM
Michael -
Unfortunately, no. Kiwi is a syslog server and none of the Cisco IPS sensors support syslog to send event messages.
If you only have a few sensors, grab a copy of the free IDM. It will pull events off IPS sensors via a secure protocol (SDEE)
http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/idm/idm_getting_started.html
Alternately, you can go in and tune the "action" of each signature you want an event send to transmit them via an SMNP Trap. This is a less secure way of sending events and you will have to keep up your action tuning as new signatures are added to your sensors over time.
- Bob
09-13-2011 04:54 PM
By the way, this is an IDSM-2 (WS-SVC-IDSM-2)
Thanx
09-14-2011 08:24 AM
Michael -
Unfortunately, no. Kiwi is a syslog server and none of the Cisco IPS sensors support syslog to send event messages.
If you only have a few sensors, grab a copy of the free IDM. It will pull events off IPS sensors via a secure protocol (SDEE)
http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/idm/idm_getting_started.html
Alternately, you can go in and tune the "action" of each signature you want an event send to transmit them via an SMNP Trap. This is a less secure way of sending events and you will have to keep up your action tuning as new signatures are added to your sensors over time.
- Bob
10-17-2011 06:10 PM
Thanx Bob. Did as you suggested, nice tool.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide