09-21-2011 01:22 PM - edited 03-10-2019 05:29 AM
folks
i've posted a query on this yesterday but i tried a couple of things and seem to have got further
if i point my collector (not mars) to the aip-ssm-20s management IP i get a connection and if i browse to it i can see the contents of the event store
Q1:
is this the correct configuration
Q2. Cisco IME shows i have 1700+ active signatures and 1688 enabled but when i ssh to the card and do a show conf or a more current i can only see
the signatures below
why!
signatures 1250 0
status
enabled true
exit
exit
signatures 2000 0
status
enabled true
exit
exit
signatures 2001 0
status
enabled true
exit
exit
signatures 2001 1
status
enabled true
exit
exit
signatures 2001 2
status
enabled true
exit
exit
signatures 2002 0
status
enabled true
exit
exit
signatures 2003 0
status
enabled true
exit
exit
signatures 2004 0
status
enabled true
exit
exit
signatures 2005 0
status
enabled true
exit
exit
signatures 2006 0
status
enabled true
exit
exit
signatures 2007 0
status
enabled true
exit
exit
signatures 2008 0
status
enabled true
exit
exit
signatures 2009 0
status
enabled true
exit
exit
signatures 2010 0
status
enabled true
exit
exit
signatures 2011 0
status
enabled true
exit
exit
signatures 2012 0
status
enabled true
exit
exit
signatures 2100 0
status
enabled true
exit
exit
signatures 3001 0
status
enabled true
exit
exit
signatures 3010 0
status
enabled true
exit
exit
signatures 3030 0
status
enabled true
exit
exit
signatures 4001 0
status
enabled true
exit
exit
signatures 4003 0
status
enabled true
exit
exit
exit
thanks to anyone taking the time to reply
09-21-2011 02:35 PM
Q1. Yes, you should always pull your SDEE events form the management IP address.
Q2. Only the signatures that differ from the default settings will appear in the "show confg" output, not all the signatures.
- Bob
09-24-2011 12:20 AM
Since you do not have an ip address on any other interface of the IPS there is no other way to connect on any other interface,
So yes you have done the right configuration.
Secondly
For any signature that has been tweeked as in modified in any way, including enabled, disabled or even retired so basically that is not in its default state will end up showing in the configuration.
So there is noting to worry about this.
Regards,
Sachin
09-25-2011 02:26 AM
sachin
again, many thanks for your contribution
greatly appreciated
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide