cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
267
Views
0
Helpful
1
Replies

Accessing IDS MC & Sec Mon db directly

csimpson
Level 1
Level 1

Can anyone tell me how I would connect directly to the database that comes installed with VMS 2.1? What ODBC drivers should I use? I'm running it with the default installation settings (except for the password), so I know the password and port (10033).

1 Reply 1

zheeter
Level 1
Level 1

It isn't possible as far as I know (if you are talking about the events)... Cisco uses a sybase db and you cannot recover the admin password even if it resides on your machine. We considered sending the db to sybase and having them crack it but we decided that wouldn't have worked since cisco owns the license to it and would not want us to do that. Basically, if you want to get at the events, you either need to parse the sensor log files or have the db spit out a comma delimited version (for 3.1) or make your own xml frontend that will grab the events from the sensor and put them in a db (for 4.1).