×

Warning message

  • Cisco Support Forums is in Read Only mode while the site is being migrated.
  • Cisco Support Forums is in Read Only mode while the site is being migrated.
mkodali Wed, 05/16/2012 - 11:31
User Badges:
  • Cisco Employee,

IPS logs are stored in the form of events. These events can be retrieved using SDEE (Security Device Event Subscription) from an external client. The event retrieval operations begin with a client initiating an unencrypted HTTP or an encrypted HTTP over TLS/SSL connection with the sensor over which event requests and responses will be communicated. Once a connection is established, the client may initiate requests to the sensor. The sensor acts on the requests and responds back to each of the client's requests with a response.

There is another type of logs called iplogs which are binary files captured on the interfaces. These can be directly copied off the sensor using "copy iplog" command.


Hope this helps.

Madhu

Actions

This Discussion