cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
341
Views
0
Helpful
2
Replies

Ids does not work! It cannot see any attack?

net-wolf
Level 1
Level 1

ids is 4230

command 'snoop -d spwr' work well and see many network flow,not only broadcast messages.

command ' nrconns' display that the ids sensor established connections with cspm2.3.3i.

but I did'nt found any attack log in cspm "tools|view sensor events|databse",

only found some event such as route up ,route down,post office initial notification.

What's wrong whit it ?

How to tell the ids sensor work well while attack take place?

Please drop me a note.

1 Accepted Solution

Accepted Solutions

jekrauss
Level 1
Level 1

Have you pushed your config from CSPM (approve now)?

If so, on your sensor, check to see if packetd is running:

nrstatus should show it's running.

If it's not running, then you need to push the config out from CSPM.

If it is running, but you're not seeing events, then you may not have the correct NameOfPacketDevice in your file:

/usr/nr/etc/packetd.conf

make sure that it's spwr0

HTH

Jeff

View solution in original post

2 Replies 2

jekrauss
Level 1
Level 1

Have you pushed your config from CSPM (approve now)?

If so, on your sensor, check to see if packetd is running:

nrstatus should show it's running.

If it's not running, then you need to push the config out from CSPM.

If it is running, but you're not seeing events, then you may not have the correct NameOfPacketDevice in your file:

/usr/nr/etc/packetd.conf

make sure that it's spwr0

HTH

Jeff

net-wolf
Level 1
Level 1

Thank you very much .

A new question:

CSPM-2.3.3i-S33-exe DOES NOT support IDS Sensor Version 3.1(2)S25 ?

please see the new post.