cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
502
Views
0
Helpful
3
Replies

Event retrieval

manmeetshergill
Level 1
Level 1

Hi,

i am running a network having 30 IPS (which indcludes SSM20s, IDSMs and IPS 44XX).

i dont have mars device. Is there any way to retrieve events from all the IPS to one central location using csmanager ??

or is there any freeware that can do the job.

Thanks in advance

3 Replies 3

rhermes
Level 7
Level 7

CSM doesn't collect events, it can only be used to manage the signatures and configurations on your sensors. To collect events you'll need a SIM like MARS, NetForenisics, Intelitactics that has an SDEE (version 7.x has a newer protocol that is backards compatible with SDEE, I forget it's name) listener.

There were some open source pieces you could try to put together yourself, but nothing I know of that is preassembled.

Alternately, you could option all your enabled signatures to fire off an SNMP trap and collect those with a free SNMP receiver.

Thanks for the reply.

i tried receiving events with an CA`s snmp receiver but the events i m receiving are not readable ..

can u sugggests any receiver.

You may use OpenNMS as free traps receiver.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card