cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2084
Views
10
Helpful
2
Replies

IPS packet captures-disk space

jason.giambrone
Level 1
Level 1

I have been doing packet captures on High and Medium events and in the IME there is no obvious way to delete old captures. They don't take up alot space but I wanted to know if there is a way to view the disk capacity on the IPS and how I can delete old capture files from the IPS.

2 Replies 2

Justin Teixeira
Level 1
Level 1

Hi Jason,

     The ip logging functionality stores the logs in a circular buffer, so there is no need (and no supported way) to delete/manage the old log files - they will be overwritten then new logs necessitate it. 

All of the information on ip logging can be found here:

http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/cli/cli_ip_logging.html#wp1030704

Also, unless you have a specific need for full stream captures for all high/medium events, you can use the "Produce Verbose Alert" action instead of the ip logging actions to capture the offending packet with significantly less resource utilization per alert.

-JT

Thanks Justin. I have been relying on the packet captures because the email notifications are not working as you know.

Jason

Review Cisco Networking for a $25 gift card