Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Users might experience few discrepancies in Search results. We are working on this on our side. We apologize for the inconvenience it may have caused.
New Member

Importing and exporting SM events

I'm looking for recommendations on the best way to archive(export) my events from Security Monitor for at least 4 weeks and if asked...import the event log into SM for research. All of my sensors are at the 4.x version. Is that even possible???

4 REPLIES
Cisco Employee

Re: Importing and exporting SM events

Read through this section of the user's guide and the sections following it:

http://www.cisco.com/univercd/cc/td/doc/product/rtrmgmt/cw2000/mon_sec/secmon12/ug/ch07.htm#130939

You will see that you have 2 options for saving off version 4.x alarms from Security Monitor.

You can use IdsAlarms.exe to export the alarms in IDIOM format (native 4.x format) and then use additional options to delete and purge the alarms from the database.

Then use IdsImportIdiom to re-import the alarms.

The IDIOM format is nice to have when you will be loading the alarms into other management boxes. Because the alarms will be in standard 4.x IDIOM format the other management box won't have to understand specific formats for Security Monitor.

The other option is to archive that alarms in a format specific to Security Monitor (a comma delimited format that can archive the IDS alarms as well as the other data collected by Security Monitor)

You would use the IdsPruning utility to export the alarms and prune them from the database.

And then use the IdsImportArchivedData utility for re-importing them into security monitor.

Since they are in a security monitor format this works fine and reduces space when they will only be imported back into security monitor. But if you will be importing them to other types of management stations (or your own database) then I recommend using the IdsAlarm.exe with the IDIOM format.

New Member

Re: Importing and exporting SM events

I turned off the IDS_receiver process and I ran the command idsimportidiom -f"test.txt" and it continues to say the IDS_receiver process is still running. Am I missing something???

New Member

Re: Importing and exporting SM events

New question...I added -d and it seemed to go through, but now I receive this:

IDS Import Idiom Parsing Error

XML Parser Not Well Formed (invalid token)

HELP!!!

Cisco Employee

Re: Importing and exporting SM events

You have gone passed my area of expertise.

I've sent a request to the VMS team for assistance but it may be a day or more to get a response.

If anyone else on the forum has experience here then please respond.

Your other option is to contact the TAC for assistance. They have a more direct line to the developers and may get you some assistance sooner than I can.

101
Views
0
Helpful
4
Replies
CreatePlease to create content