Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Cisco IPS Action "Log attacker packets"

Forum

we have both and IPS 4240 as well as one of the newer IPS 4345 IPS units in place at this specific customer site.

When I drill down into IME into Event Monitoring on the IPS 4345, I can see we are having multiple signature matches from

IPS_UPnP Location Overflow.jpg

I have this configured currently for Actions to take as:

actions.jpg

What I want to do is see if I can determine what workstation this is coming from.  How would I be able to see the attacker packets which are logged? 

I do not see a way in IME to view attacker packets.  I think there used to be a way in the old IDM app to do this, but I am not sure how anymore?

Thanks in advance!                  

147
Views
0
Helpful
0
Replies