Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

IDSM troubleshooting

How to diagnose whether the IDSM is monitoring traffic. What are the steps.

3 REPLIES
Gold

Re: IDSM troubleshooting

Check that the IDSM-2 is getting traffic. On the CLI do a "show interface"

Check if the traffic is getting to the analysis engine with a "show stat anal"

(if you're not seeing your taffic in the analysis engine, you forgot to add the interface to the virtual sensor)

Then turn on sig 2004 (ICMP echo reply) and run a few pings past the sensor to see if you are getting sigs to fire.

New Member

Re: IDSM troubleshooting

Both the above coands are working fine. How ever I am not geting any alerts on the event viewer.Pls help on this.

Re: IDSM troubleshooting

Can you post the "show config" of the IDSM and "show run | inc intrusion" of the core switch?

Regards

Farrukh

183
Views
0
Helpful
3
Replies