11-16-2009 11:17 AM - edited 03-10-2019 04:49 AM
Hi folks,
Is there anyway to see the number of EPS a particular IPS sensor generates while being connected to it via telnet?
What's the size of the events store? And how can SDEE pull old events from the store?
11-16-2009 02:28 PM
You'll have to do a little math to come up with that number yourself:
"show stat analysis"
then take the output lines:
Number of seconds since service started = 10887
Number of SigEvents since reset = 37360
and devide the sigevent count by the number of seconds.
The event store is a fixed size (and I don't remember how big they made it in flash) but the events are variable in size. SDEE can be used to pull old events because the client (your SIM, MARS, etc) requests events from the server (your sensor) much like you do when querying the event store from the CLI.
"show event alerts past 23:39"
11-16-2009 04:10 PM
Wow,
Never knew about such calculations. Thanks a lot!
Were these statistics from a busy IPS sensor? I don't seem to exceed 10 EPS and thought this is low. And I wouldn't think that calculating the size of every event is tricky?
Simply copying the details of every event into notepad gives me the size of every event about 1K.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide