02-02-2005 01:48 AM - edited 03-09-2019 10:12 AM
Hi,
I was wondering if anyone with some SIMS experience could assist.
I have taken a look at all of the administration and configuration guides available for SIMS on the web and I have found them a bit unclear.
Does anyone perhaps have some additional material that they could share that would assist in the install ?
My second question is regarding the collection of the logging information coming off the PIX firewall IDS and network appliance IDS. Does one simply configure the SIMS server as a destination for syslog messages ?
I see that there are agents , what are these agents for ?
Any assistance would be greatly appreciated.
Many thanks
Tony
02-08-2005 04:07 AM
Hi,
I didn't come across any additional guides, but I agree - it`s al little bit difficult to understand the technical view behind with the given documentation.
Devices capable of forwarding syslogs do this directly to the SIMS, otherwise SIM software agents have to be used.
In our lab. we used 4 PIXs, 2 Netranger IDS appliances, CSAMC logging and Windows hosts(event log).
All but the PIXs needed the software agents for fetching their logs. In case of Windows hosts you need one client agent per host. For IDS appliances you need only one agent and configure it to fetch the logs via SSL account.
Regards,
Arne
02-08-2005 10:57 PM
Hi Arne,
Thanks for your reply,
Quick question how did you get the logging information from VMS to SIMS, in particular CSAMC. If you can point me to the docs that assisted you that would be a great help.
Many thanks
Cheers tony
02-08-2005 11:40 PM
Hi Tony,
1) Log in to CSAMC
2) Under Monitor create a new Alert:
- select ALL events
- select Log file and type in a absolute destination path.
(This log export of the CSAMC Event Log is called Message file in the installation process of the CSA SIM agent/client.)
4) Install CSA SIM Agent. I recommend to install it directly on the Cisco Works server. During installation point to the new generated Message file. Done.
(You only need one CSA SIM agent which fetches the export of the CSAMC event log and forward it to the SIMS.)
Regards,
Arne
02-09-2005 12:07 AM
Hi Arne,
Thanks for your prompt reply, we have the SIMS hardware appliance, any idea where I can download the agents that need to install on CiscoWorks VMS
Thanks again
Tony
02-09-2005 12:23 AM
02-09-2005 12:30 AM
Thanks
will give it a go and let you know how it goes.
Thanks
Tony
02-09-2005 02:40 AM
Hi Arne,
I logged onto the VMS server and created a new log alert and pointed it to a file called SIMS.log. I would expect all the events that appear on CSAMC to appear in this file correct ?
I then ran the file nf.installagent.exe and selected Cisco Security Agent from the various agents that are available, I am prompted for the SIMS ip address for engine and database. It then pops up with an error.
Am I following the correct process ? It seems as if the agent is what is responsible for sending all the events that are now replicated to that log file and sent to SIMS server for processing, am i on the right track ?
Thanks
Tony
02-09-2005 02:47 AM
Hi Tony,
Q1) Yes, this is a 1:1 export of what is displayed on the event console.
Q2) You are right. Setup the SIMS (including FQDN) and afterwards point the agent to the DNS or IP of the SIM when asked. The agent forwards events out of the SIMS.log in realtime to SIMS.
Regards,
Arne
02-09-2005 02:57 AM
Hi Arne,
Great stuff, thanks it is making a whole lot more sense now, one other question do I have to add the CSAMC as a device on the SIMS server ?
Tony
02-09-2005 03:46 AM
When the SIM agent established a connection with the SIM it autom. registers. If this happened successful you will notice that the reported devices will be listed in Administration Panel as unconfirmed devices. These have to confirmed and put into self defined logical groups. Therefore all active reporting CSAs will be listed in Device Status on the SIM. So there`s no need to add the CSAMC except the CSA protecting the Cisco Works server which gets listed under the other CSAs.
Regards,
Arne
02-11-2005 05:40 AM
Hi Arne,
We reimaged the Sims Box and now the syslog agent is not running any longer, so we are not receiving event logs from devices, any idea how you restart the syslog agent ?
PS we have the solution engine running , with the version running on Linux it was easy, the appliance is a little different you dont have access to the linux command line.
Thanks tony
02-11-2005 06:45 AM
Hi Tony,
on the appliance you`ll have to telnet in(CLI), do a 'rootenable' and afterwards you could use 'su' command for bash access.
Which syslog you mean? Local syslog start: /etc/init.d/syslog start|stop
On CLI you have the chance of using 'nfadmin'
(The problem could be, by reimaging of the image-DVD you often get a very old version status. We had to install a bunch of updates until current version for stable service operating.)
Regards,
Arne
10-22-2008 08:41 AM
Hello. Do you still have access to a Cisco SIMS Engine?
10-22-2008 08:40 AM
Hello. Do you still have access to a Cisco SIMS Engine?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide