cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
403
Views
0
Helpful
1
Replies

IEV for IDSM2 can't view the realtime events.

alomar818
Level 1
Level 1

When I try to use the IEV to monitor the IDSM's realtime events,it can work successfully after I reset the IDSM.But after many hours the IEV's realtime dashboard can't view the events.I can see the IEV connect to IDSM is ok.I check the IDSM CLI by show version command that all things are in "Running" states.The IEV can't connect to IDSM when the AnalysisEngine NotRunning.But now all things are ok the IEV connect to IDSM successfully,why the IEV realtime dashboard can't see the events?Does anybody know what is happened?My IDSM firmware version is 4.x.I used the data-port 1 and 2 to monitor the traffic.Some information bollow:

6509#sh intrusion-detection module 8 data-port 1 traffic

Intrusion-detection module 8 data-port 1:

Specified interface is up line protocol is down (monitoring)

Input queue: 0/2000/0/0 (size/max/drops/flushes); Total output drops: 0

5 minute input rate 0 bits/sec, 0 packets/sec

5 minute output rate 93437000 bits/sec, 18180 packets/sec

6509#sh intrusion-detection module 8 data-port 2 traffic

Intrusion-detection module 8 data-port 2:

Specified interface is up line protocol is down (monitoring)

Input queue: 0/2000/0/0 (size/max/drops/flushes); Total output drops: 11092643

5 minute input rate 0 bits/sec, 0 packets/sec

5 minute output rate 237669000 bits/sec, 41849 packets/sec

With these data hope can provide some information to troubleshooting.I don't know it's means that data-port 2 Total output drops: 11092643.Does anybody know the answer? Thanks your response a lot.

1 Reply 1

pradeepde
Level 5
Level 5

Running native code on catalyst 6000/6500 switches the IDSM module has two sniffing ports. IOS recognize these ports as logical and physical ports. The logical ports are 1 and 2 and the physical ports are 7 and 8

Review Cisco Networking for a $25 gift card