cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
223
Views
0
Helpful
1
Replies

customized reporting/grep ids 4.x

cpeluso
Level 1
Level 1

In the version 3.x of cisco ids, I could grep the ids log files any way I want. For example, I would like to see all the alerts on a specific port and I could write a grep to do that. How can I get this type of detailed, custom or specific report out of the 4.1(4)S126 sensor? The canned reports don't do it.

1 Reply 1

ktimm
Level 1
Level 1

Write an xml parser to put it in the format you want. Do this after logs have been gathered through RDEP. There are probably better solutions but that is the one I know of.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: