Cisco IPS Event Viewer & ASA-SSM10

Unanswered Question
Aug 7th, 2007

I've setup IP Logging on the sensor and can download the packet dumps via the IDM interface and then view via Ethereal on my PC.

How do I get this working via IEV? The menu option 'Show Captured Packet' is always greyed out. I have set the path to Ethereal in 'Application Settings'

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
marcabal Tue, 08/07/2007 - 07:28

There is a misunderstanding in what IEV is capable of doing.

IEV does not have the ability to download and view iplogs.

The "Show Captured Packet" option in IEV is for viewing the trigger packet of the alert that gets added to the alert itself rather than part of an IP Log.

The trigger packet gets added to the alert when the Produce Verbose Alert event action is added to the signature.

The Produce Verbose Alert adds the trigger packet to the alert (it base 64 encodes the packet when adding it to the alert). IEV can then decode the packet and make it viewable to the user.

The Packet Log actions log the packets into a iplog. It will Also include the trigger packet, but also includes additional packets. The IP Logs are not currently downloadable and viewable through IEV.

Actions

This Discussion