cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
433
Views
0
Helpful
1
Replies

too frequent ftp of logs

jeff.gift
Level 1
Level 1

Hi,

I would simply like to ftp the logs off the IDSM to the ftp server once a day. My IDSM is sending them about every two minutes. Is there a setting somewhere other than the sapd config?

Thanks!

1 Reply 1

wardwalk
Cisco Employee
Cisco Employee

Hi Jeff,

Have you recently enabled log file ftp on your IDSM? It's likely that the log files being ftp'ed are older closed log files that have collected before log file ftp was enabled. Once these have all been ftp'ed, the ftp frequency should decrease because log files will only be ftp'ed as they're closed. Log files are closed on a time basis and a size basis. So, each time a log file gets full or too old, it's closed and is ftp'ed off.

If you're still seeing too frequent ftp'ing of log files, you may want to adjust what signatures your IDSM is alarming on.

Hope that helps.

Ward.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: