Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Forwarding IDS logs to Symantec SSIM

Hi,

I want to forwards Cisco IDS logs to Symantec Security Manager device. But i am not getting procedure for implementing it.

Thanks & Regards,

Shamsundar.

1 REPLY
Gold

Re: Forwarding IDS logs to Symantec SSIM

Check if your Symantec Security Manager supports SDEE, if it does, make it an SDEE client to the sensor's SDEE server.

If it doesn't you'll have to modify each signature (or globally via an event action override) you want an event sent and enable the request-snmp-trap action. This will cause a trap to be issued when those signatures fire. The SNMP trap will contain less information than the SDEE message.

http://www.cisco.com/en/US/docs/security/ips/6.2/configuration/guide/cli/cli_event_action_rules.html#wp1113302

500
Views
0
Helpful
1
Replies