amritpatek Fri, 09/07/2007 - 10:08

The IPS device maintains a log of all events (including who has logged). However if there are lot of events happening the entries in the log gets replaced fast. You can see this log using command "show log" on the IPS device. The IPS cannot be used with Radius or TACACS for authentication or authorization.

mhellman Fri, 09/07/2007 - 14:30

From the CLI:

# show event status past 23:59 | include loginAction

I'm not sure how you'd go back farther without using the IDM (in the IDM you can tell it to show entire log buffer).


This Discussion