cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
512
Views
0
Helpful
1
Replies

Security Monitor 2.1

NAVIN PARWAL
Level 2
Level 2

Folks,

I have a couple of questions regarding IDS MC 2.1.

1) Will it generate reports giving information about lets say critical alarms or lets say informational alarms?

2) How often does it access the database. I mean lets say the attck was happening, how soon would the security monitor be able to send an e-mail about that??

1 Accepted Solution

Accepted Solutions

gabelar
Level 1
Level 1

Use SecMon with MC2.1.

It will report severity as described in question #1.

As far as #2, secmon in MC2.1 will "subscribe" to a sensor and the events are "more or less" real time. This means that once a subscrition is established the IPS appliance will send the event as it is generated. However keep in mind that if the IPS box is busy, attack interrupts take precendnce over event reporting. Bottom line is that events should be in secmon within 10-20 second of when they fired.

View solution in original post

1 Reply 1

gabelar
Level 1
Level 1

Use SecMon with MC2.1.

It will report severity as described in question #1.

As far as #2, secmon in MC2.1 will "subscribe" to a sensor and the events are "more or less" real time. This means that once a subscrition is established the IPS appliance will send the event as it is generated. However keep in mind that if the IPS box is busy, attack interrupts take precendnce over event reporting. Bottom line is that events should be in secmon within 10-20 second of when they fired.

Review Cisco Networking for a $25 gift card