12-10-2021 10:39 AM
Ok so I am not a cisco master so lets start with that. I have an AlienVault SIEM on my network and currently I am using the span ports to send all of the switch data for our uplink port to the AlienVault SPAN port. Well, we have been tasked with getting a different SIEM and running them both in place for a little while. My question is how do I configure my span port to take one source and send it to two different destinations? I tried to create a separate session using monitor session 2 instead of monitor session 1. That did not work as the new SIEM is still not getting any traffic. Anybody have any suggestions as to what to do in this instance?
Solved! Go to Solution.
12-12-2021 07:32 AM
Hello,
What is the switch model and firmware version? but meanwhile, you can try with as
destination {interface interface-id [, | -] [encapsulation {dot1q | replicate}]}
in this command, you can Specify a series or range of interfaces. Enter a space before and after the comma; enter a space before and after the hyphen
12-12-2021 07:32 AM
Hello,
What is the switch model and firmware version? but meanwhile, you can try with as
destination {interface interface-id [, | -] [encapsulation {dot1q | replicate}]}
in this command, you can Specify a series or range of interfaces. Enter a space before and after the comma; enter a space before and after the hyphen
12-12-2021 12:40 PM
Hello @Deepak Kumar
I like to convey my congratulations to you on achieving your CCIE , very well done and well deserved.
12-12-2021 09:03 PM
Dear @paul driver
Thank you so much.
12-14-2021 05:37 AM
Thank you for your help Deepak.
12-12-2021 12:20 PM - edited 12-14-2021 11:32 AM
Hello
@KyleWhitaker wrote:
My question is how do I configure my span port to take one source and send it to two different destinations?
You don't , You can only have specific destination(s) port per session
12-12-2021 09:05 PM
Hello,
I think he can as the below output is from my switch
sw10(config)#monitor session 10 destination interface gigabitEthernet 1/0/1 ? , Specify another range of interfaces - Specify a range of interfaces encapsulation Set encapsulation for destination interface ingress Enable ingress traffic forwarding <cr>
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide