The show ip
audit statistics Command
Use the show ip audit statistics EXEC command to display the number of packets audited and the
number of alarms sent, among other information. This command shows any
signatures used, how many interfaces are configured for audit, and a summary of
session information.
Rtr1#show ip audit statistics
Signature audit statistics [process switch:fast switch]
signature 2000 packets audited: [1:569]
signature 2004 packets audited: [2:569]
Interfaces configured for audit 2
Session creations since subsystem startup or last reset 3
Current session counts (estab/half-open/terminating) [1:0:0]
Maxever session counts (estab/half-open/terminating) [1:1:0]
Last session created 00:00:10
Last statistic reset never
Rtr1#
The clear ip audit statistics Command.
To reset the audit statistics for packets analyzed and
alarms sent, use the clear ip audit statistics EXEC command. This command could be handy to eliminate historical
data when trying to see current activity. If the data is being logged, clearing
these counters shouldn’t present any downside. The syntax is
Rtr1#clear ip audit statistics