cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
817
Views
0
Helpful
3
Replies

IDSM Logging to Kiwi

MBrooksAirIT
Level 1
Level 1

This may be a very naive question, if so it will certainly match my knowledge level! Can log messages be sent to a Kiwi Syslog Server? If so, how to configure?

Many thanx

-michael

1 Accepted Solution

Accepted Solutions

Michael -

Unfortunately, no. Kiwi is a syslog server and none of the Cisco IPS sensors support syslog to send event messages.

If you only have a few sensors, grab a copy of the free IDM. It will pull events off IPS sensors via a secure protocol (SDEE)

http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/idm/idm_getting_started.html

Alternately, you can go in and tune the "action" of each signature you want an event send to transmit them via an SMNP Trap. This is a less secure way of sending events and you will have to keep up your action tuning as new signatures are added to your sensors over time.

- Bob

View solution in original post

3 Replies 3

MBrooksAirIT
Level 1
Level 1

By the way, this is an IDSM-2 (WS-SVC-IDSM-2)

Thanx

Michael -

Unfortunately, no. Kiwi is a syslog server and none of the Cisco IPS sensors support syslog to send event messages.

If you only have a few sensors, grab a copy of the free IDM. It will pull events off IPS sensors via a secure protocol (SDEE)

http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/idm/idm_getting_started.html

Alternately, you can go in and tune the "action" of each signature you want an event send to transmit them via an SMNP Trap. This is a less secure way of sending events and you will have to keep up your action tuning as new signatures are added to your sensors over time.

- Bob

Thanx Bob. Did as you suggested, nice tool.

Review Cisco Networking for a $25 gift card