Configuring Manual Ip Logging For A Specific Ip Address - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Chapter 8
Configuring IP Logging
Verify the settings:
Step 6
sensor(config-sig-ip)# show settings
ip-log
-----------------------------------------------
-----------------------------------------------
sensor(config-sig-ip)#
Exit IP logging mode:
Step 7
sensor(config-sig-ip)# exit
sensor(config-sig)# exit
Apply Changes?:[yes]:
Step 8
Press Enter to apply the changes or type no to discard the changes.

Configuring Manual IP Logging for a Specific IP Address

Use the iplog name ip-address [duration minutes] [packets numPackets] [bytes numBytes] command
to log IP packets manually on the virtual sensor for a specific IP address.
The following options apply:
Note
The minutes, numPackets, and numBytes parameters are optional, you do not have to specify all three.
However, if you include more than one parameter, the sensor continues logging only until the first
threshold is reached. For example, if you set the duration to 5 minutes and the number of packets to 1000,
the sensor stops logging after the 1000th packet is captured, even if only 2 minutes have passed.
To stop logging IP packets for a specific IP address, see
packets as an event associated with a signature, see
copy and view an IP log file, see
78-16527-01
ip-log-packets: 200 default: 0
ip-log-time: 60 default: 30
ip-log-bytes: 5024 default: 0
name—Virtual sensor on which to begin and end logging.
There is only one virtual sensor name in IPS 5.0, vs0.
Note
ip-address—Logs packets containing the specified source and/or destination IP address.
minutes—Duration the logging should be active.
The valid range is 1 to 60 minutes. The default is 10 minutes.
numPackets—Maximum number of packets to log.
The valid range is 0 to 4294967295. The default is 1000 packets.
numBytes—Maximum number of bytes to log.
The valid range is 0 to 4294967295. A value of 0 indicates unlimited bytes.
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
Configuring Manual IP Logging for a Specific IP Address
Stopping Active IP Logs, page
Configuring Automatic IP Logging, page
Copying IP Log Files to Be Viewed, page
8-4. To log IP
8-2. To
8-6.
8-3

Advertisement

Table of Contents
loading

Table of Contents