cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
637
Views
0
Helpful
1
Replies

IPS logs

Hi,

My customer have a AIM-IPS and he can't log export to external server.

How can I logs export from IPS to an external server?

Thank you

1 Reply 1

mkodali
Cisco Employee
Cisco Employee

IPS logs are stored in the form of events. These events can be retrieved using SDEE (Security Device Event Subscription) from an external client. The event retrieval operations begin with a client initiating an unencrypted HTTP or an encrypted HTTP over TLS/SSL connection with the sensor over which event requests and responses will be communicated. Once a connection is established, the client may initiate requests to the sensor. The sensor acts on the requests and responds back to each of the client's requests with a response.

There is another type of logs called iplogs which are binary files captured on the interfaces. These can be directly copied off the sensor using "copy iplog" command.

Hope this helps.

Madhu

Review Cisco Networking products for a $25 gift card