cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
599
Views
0
Helpful
3
Replies

IDS Log analysis

emily
Level 1
Level 1

I got many log.YYMMDD file in my FTP server, I want to use Private-I to analysis, What tool can combine many these log.YYMMDD files become a file

Thanks your help

3 Replies 3

kleem
Cisco Employee
Cisco Employee

I am not familiar with how the Private-I tool operates, you may want to refer to their documentation about what it expects as input. Meanwhile, you ought to be able to 'cat log.* > ids.log' in the directory with the logs (on a unix host) or 'FOR %f IN (log.*) DO type %f >> ids.log' from the command prompt on a Windows host to combine all the log.date files into one file.

Thanks for you reponse , But i want what tool be used to analysis these log files

kleem
Cisco Employee
Cisco Employee

Use the Cisco IDS management application (CSPM) to receive/view alarms and create reports. CSPM communicates directly with the Sensors so that events are received in "real-time", avoiding the delay created by ftping the files periodically. Cisco does not have a separate tool which pulls in log files and analyzes them. Some of our partners, which are consumers of our alarm data, may have such a tool, but most of them take a direct feed like CSPM.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: