cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
126
Views
0
Helpful
1
Replies
Highlighted
Beginner

customized reporting/grep ids 4.x

In the version 3.x of cisco ids, I could grep the ids log files any way I want. For example, I would like to see all the alerts on a specific port and I could write a grep to do that. How can I get this type of detailed, custom or specific report out of the 4.1(4)S126 sensor? The canned reports don't do it.

1 REPLY 1
Beginner

Re: customized reporting/grep ids 4.x

Write an xml parser to put it in the format you want. Do this after logs have been gathered through RDEP. There are probably better solutions but that is the one I know of.