12-03-2013 07:47 PM - edited 03-10-2019 06:06 AM
Hi IPS Expert,
I am managing and monitoring IPS using IPS Manager Express installed on my workstation.
I replace my workstation a week ago and reinstall IME.
I noticed that i can no longer retrieve old events.
1. Are the old events stored on the first machine?
2. How to backup the logged events?
Regards,
Jhun
12-03-2013 08:08 PM
1. Are the old events stored on the first machine?
yes, IME uses an internal database to store all events.
2. How to backup the logged events?
Under "File" you have the option to export on one machine and import on another.
--
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni
12-03-2013 09:24 PM
Thanks for the reply.
1. Do we have retention period of events?
2. If yes, where can we view or set the retention period?
3. Is the retention period only applicable on the machine where the IME is installed?
-Jhun
12-04-2013 01:04 AM
you have to configure Archiving on the IME to clean up the local Database:
http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/ime/ime_getting_started.html#wp1240406
Sent from Cisco Technical Support iPad App
12-08-2013 05:45 PM
Thank you for the response karsten. This is very helpful.
I have further inquiry. Noticed that after going through the archiving event options, we can schedule the archiving at maximum 24 hours interval.
a. Where will the archived data stored and?
b. Can we still view alarms from archive?.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide