Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)

IPS logs

Hi,

My customer have a AIM-IPS and he can't log export to external server.

How can I logs export from IPS to an external server?

Thank you

Everyone's tags (2)
1 REPLY
Cisco Employee

IPS logs

IPS logs are stored in the form of events. These events can be retrieved using SDEE (Security Device Event Subscription) from an external client. The event retrieval operations begin with a client initiating an unencrypted HTTP or an encrypted HTTP over TLS/SSL connection with the sensor over which event requests and responses will be communicated. Once a connection is established, the client may initiate requests to the sensor. The sensor acts on the requests and responds back to each of the client's requests with a response.

There is another type of logs called iplogs which are binary files captured on the interfaces. These can be directly copied off the sensor using "copy iplog" command.

Hope this helps.

Madhu

355
Views
0
Helpful
1
Replies
CreatePlease to create content