cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
323
Views
0
Helpful
1
Replies

SECMON 2.1 and IPS 5.0

mkirbyii
Level 1
Level 1

When an event shows up in the event viewer the details pane to the right has all the details of the event. One of the sections is "Response" it lists "IP Logged: True/false" etc. If I have a sig with an action of "deny packet inline" shouldnt I see something in the "response" section? I guess I thought I would have a way of knowing what action the sensor took for the sig. Is there a way within the event viewer to know what action the sensor took?

1 Reply 1

umedryk
Level 5
Level 5

It is the response that you would like your IDS box to perform. It can shut the host, drop the tcp connection etc.

Review Cisco Networking for a $25 gift card