Reporting and Alert Querying

Unanswered Question
Jan 18th, 2008

I'm just getting started with my IDS/IPS SSM-20 module. I'm looking for some reporting and querying capabilities for it. Is there a function or ability within the IDM 5.1 application or even if I upgrade. Is possible to look for all alerts for a particular IP address or a specified signature? Can I generate a report on how many attacks were mitigated?

Any help would be appreciated.

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)

Both IDM and "show events alert" have very basic querying capabilities. The only thing you can do is to mark some signature with "traits" code and show alerts fired by this signature with:

sensor# sh events alert include-traits ?

<0-15> Traits to include in the show events output.

Try IDS Event Viewer. IEV is a free tool that can be downloaded from the Cisco website. But is very limited too. The primary Cisco product for viewing/reporting is the Cisco MARS. But it is expensive...

rolandshum Thu, 01/24/2008 - 07:56

I was afraid of that. Even though I'm looking into MARS I hate to have my decision tied to improving the functionality of a product I already have.


This Discussion