Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

IDS can integrate with another RDBM that is not Oracle

Can I configure for Sensor to send iplog files to another RDBM such as MySQL? How can I accomplish it?

3 REPLIES
Cisco Employee

Re: IDS can integrate with another RDBM that is not Oracle

First to clarify log file naming conventions.

There are the log files containing alarms (it also contains records of commands and errors), and there are iplog files which contain the binary data from packet captures.

If you are talking about the alarm logs then continue reading below, but if you are talking about iplogs (raw binary packet data) then I don't know if you really want to try loading them into a database. The iplogs generally need to be parsed and interpretted with a tool like ethereal, and even then it is more a viewable format than one that can be loaded into a database. The sensor also does not provide an automated means of retreiving the iplog files from the sensor.

If you are talking about alarm logs then read the following:

If you are using the Unix Director and not CSPM then follow the instructions in the following section of the Unix Director Config Note:

http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids7/unix_cfg/rdbms.htm#xtocid1886819

If you are using CSPM then you will have to implement most of this yourself.

The following steps are a good starting point:

1) Determine how the alarm log file will be sent to your machine running MySQL.

CSPM has a cvtnrlog script that can be run to create a log file from the alarms stored in the CSPM database. You would need to find a way to schedule cvtnrlog to run and copy the files to you MySQL machine.

Alternatively, you could use the built in automated ftp functionality of the sensor. The sensor can be configured to automatically ftp it's log files off to an ftp server every time a log file is closed. The ftp server would be the machine with MySQL. The ftp funcionality is configured within CSPM for the sensor.

2) Create the tables in your database.

The Unix Director Config Note provides the Oracle Schemas that you can convert to MySQL:

http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids7/unix_cfg/schemas.htm

3) Build a script to load the log files into your database.

This script you or your database administrator will need to write.

4) Setup the script to run automatically when it sees a log file having been ftp'd from the sensor or copied from the cvtnrlog utility.

If you are using a Unix box, then setting up a simple crontab to run the script and check for new log files will work well.

New Member

Re: IDS can integrate with another RDBM that is not Oracle

I setup mysql to do this last year -- let me know if I can be of assistance.

-brkn!

New Member

Re: IDS can integrate with another RDBM that is not Oracle

Have you wrote any basic sql queries ???. If yes, i'm interrested to get some....

thanks

80
Views
0
Helpful
3
Replies