Header
Home | Set as homepage | Add to favorites
  Search the Site     » Advanced Search
Sections
Syndication


Blogroll:

||||| ALL Cisco-Network ARTICLES |||||  
CCIE Journey,
The CCIE Journey,


Configuring Event Logging (IDS version 3.1)

Nov 24,2008 by admin

image

Configuring Event Logging (IDS version 3.1)

Depending on what the sensor had been configured to watch, it can generate audit event logs locally on the sensor based on syslog data streams, network data streams, or both. Follow these steps and examine Figure 5.17 to see how events will be logged:

Click To expand
Figure 5.17: Using 3.1 IDM to Configure Logging
  1. In the IDS Device Manager main window, select Configuration | Logging | Event Logging.

  2. The Event Logging panel appears. Select the Enable check box. Once event logging has been enabled, the only two options that can be set are the Level and Type options.

  3. Select the severity level of the signature from the Level list box:

    • Information   Attacks not relevant to security are categorized. These attacks are shown in the IDS Event Viewer with a blue icon.

    • Low   Mildly severe attack. These attacks are shown in the IDS Event Viewer with a yellow icon.

    • Medium   Moderately severe attack. These attacks are shown in the IDS Event Viewer with an orange icon.

    • High  Highly severe attack. These attacks are shown in the IDS Event Viewer with a red icon.

  4. To specify types of events you want to log, select one or more of the Type check boxes.

  5. Click OK.

If alarm events are selected to be logged, then all alarms for enabled signatures which have severity levels that are greater than, or equal to, the selected level chosen in the Event Logging Panel are logged to the file /usr/nr/var/log/log.timestamp. If IPLogs are desired as well, then the severity level must be set to Information. IPLogs are stored in a binary format in the /usr/ne/nr/iplog/iplog.address.timestamp files.


Note 

ComdLogs, Errors, and Alarms are also written to the event logs.

To view the event log files, select Monitoring | Logs in the IDM browser window.


319 times read

Related news

» Configuring Logging
by admin posted on Nov 24,2008
» Event Viewer
by alperen posted on Mar 17,2010
» Configuring IP Logging
by admin posted on Nov 24,2008
» Event Viewer Customization
by alperen posted on Mar 17,2010
» Exporting Event Logs for cisco ids
by admin posted on Nov 24,2008
Did you enjoy this article?
(total 0 votes)

comment Comments (0 posted) 

More Top News
CCSP-Cisco Certified Security Professional
Most Popular
Most Commented
Featured Author