11-19-2001 04:26 PM - edited 03-08-2019 09:13 PM
Hey all,
For the life of me I cannot figure out how to view the log files sent to the sensor when "ip log" is set for the action on the signatures. I know where they are in the sensor, they are raw data files tho. How do you read these ? I am assuming they are similar to a sniffer trace with all the packet info in them. Tried ftp'ing them and opening them with sniffer pro, didn't work tho. Can someone point me in the right direction ?
Thanks,
Brian
11-20-2001 06:30 AM
IDS 2.X IP log files can be viewed using Ethereal (www.ethereal.org).
IDS 3.X IP log files are in tcpdump format.
11-20-2001 07:02 AM
Thanks, btw it's www.ethereal.com .org was some tarot card place ! LOL I'm running 3.0(4)s4 on the sensor already. You said it's in tcp dump format, how do I view those, again, it appears to be raw data. I tried sniffer pro, didn't work. I'll try the ethereal today if I get a chance.
Thanks,
Brian
11-20-2001 09:01 AM
IPLOGS from version 2.x sensors were in a proprietary binary format, and could only be read by ethereal and a special program called transcript that was on the 2.2.1 Unix Directors.
IPLOGS from version 3.x sensors are in standard tcpdump format, and can still be read by ethereal, and can now be read by any other tool able to read tcpdump formatted files.
(NOTE: transcript on the director can not read the new tcpdump format)
01-28-2002 12:06 PM
MARCOA,
Is the ip log feature in cspm not available with the IDSM 3.0(3)S10? I have enabled this for a few signatures but do not see any logs on the IDSM?
Thank,
Jeff
01-28-2002 12:22 PM
The IDS Module does not support IP Logging.
You have to have the IDS Appliance for IP Logging.
11-21-2001 09:50 AM
If you recieved the CD for the upgrade to 3.0 onthe sensor, Ethereal comes with it and iplogs can be viewed from the director. You can also put it on a Windows machine. I FTP the files down to my Win2k machine and view them with Ethereal there.
11-24-2001 02:51 PM
Excellent, Thanks Robert. I didn't even look on the 3.0 disk, figured it was straight unix/linux. Looked on the cspm disk, nada. I'll check out the 3.0 disk tommorow. Thanks again.
Brian
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide