12-21-2004 01:42 PM - edited 03-10-2019 01:12 AM
I have an IDS running 4.1.4 S131. It has working few about two months now, but all of a sudden I stopped getting alerts. I clear my events thinking that it reached it's maximum, but still no alerts. if anyone can help I'd really appriciate it.
Thanks
12-23-2004 04:49 PM
you need to separate this issue
1- IDS seeing alerts or not
2- Alerts coming into security monitor or not
for 1
login to IDS and type
"show event alert past 4:00"
see if you got any alerts in say past 4 hours. if you are getting alerts, and those same alerts are not appearing on security monitor. then the most posssible cause is DB corruption. DB size may have grown up too large to handle.
if that is the case, you can try to do a few DB tunning , but most probably you will end up in reinstall of security monitor.
here is the link for DB tunning.
http://www.cisco.com/univercd/cc/td/doc/product/rtrmgmt/cw2000/mon_sec/secmon20/ug/dbrules.htm
thanks
Nadeem
12-23-2004 04:54 PM
Thanks, i think I got it fixed. It seemed to be stuck in one of it's processes. i saved and reset and that seemed to do the trick.
Thanks for the link!
12-26-2004 08:14 AM
links work
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide