cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1472
Views
0
Helpful
4
Replies

IDSM2 logging

000000jbl
Level 1
Level 1

Is it possible to send events from the IDSM2 to two different aggregation points simultaniously?  Say for instance, Cisco MARS and some other SIEM.

4 Replies 4

Jim Thomas
Level 4
Level 4

Yes, you can use mars or IME (any combination) to both simultaneously pull alerts using sdee from the sensor.

Jim Thomas Cisco Security Course Director Global Knowledge CCIE Security #16674

Farrukh Haroon
VIP Alumni
VIP Alumni

MARS and IME both use the 'pull' event architecture to retrive events from IPS devices, and as already answered both can 'pull' events from the same IPS device simultaneously without any issues (except the performance lag). IME will store events in its MSDE database and MARS has its own oracle database (which can be archived using unix NFS). IME is limited to 10 sensors tough.

Regards

Farrukh

Ok, so do I understand correctly that there is no way to have IDSM send its logs out to a generic log server?  I undersatd SDEE and the "pulling" of events from IDSM.  Is there no way to have IDSM push?  Maybe via syslog rather than SDEE?

You are correct, the IPS does not support syslog reporting. You can enable SNMP traps on a per signature basis tough. But once has to be careful not to over whelm the IPS Cpu/memory resources in doing so.

Regards


Farrukh

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card