How to see EPS (events per second) at IPS from CLI

Unanswered Question
Nov 16th, 2009

Hi folks,

Is there anyway to see the number of EPS a particular IPS sensor generates while being connected to it via telnet?

What's the size of the events store? And how can SDEE pull old events from the store?

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
rhermes Mon, 11/16/2009 - 14:28

You'll have to do a little math to come up with that number yourself:

"show stat analysis"

then take the output lines:

Number of seconds since service started = 10887

Number of SigEvents since reset = 37360

and devide the sigevent count by the number of seconds.

The event store is a fixed size (and I don't remember how big they made it in flash) but the events are variable in size. SDEE can be used to pull old events because the client (your SIM, MARS, etc) requests events from the server (your sensor) much like you do when querying the event store from the CLI.

"show event alerts past 23:39"

zheka_pefti Mon, 11/16/2009 - 16:10


Never knew about such calculations. Thanks a lot!

Were these statistics from a busy IPS sensor? I don't seem to exceed 10 EPS and thought this is low. And I wouldn't think that calculating the size of every event is tricky?

Simply copying the details of every event into notepad gives me the size of every event about 1K.


This Discussion