Gathering Information
traits—Trait bit position in decimal (0 to 15).
•
error—Displays error events. Error events are generated by services when error conditions are
•
encountered.
log—Displays log events. Log events are generated when a transaction is received and responded to
•
by an application. Contains information about the request, response, and success or failure of the
transaction.
NAC—Displays Network Access Controller (block) requests.
•
status—Displays status events.
•
•
past—Displays events starting in the past for the specified hours, minutes, and seconds.
•
hh:mm:ss—Hours, minutes, and seconds in the past to begin the display.
The show events command waits until a specified event is available. It continues to wait and display
Note
events until you exit by pressing Ctrl-C.
To display events from the Event Store, follow these steps:
Log in to the CLI.
Step 1
Display all events starting now:
Step 2
sensor#@ show events
evError: eventId=1041472274774840147 severity=warning vendor=Cisco
originator:
hostId: sensor2
appName: cidwebserver
appInstanceId: 12075
time: 2003/01/07 04:41:45 2003/01/07 04:41:45 UTC
errorMessage: name=errWarning received fatal alert: certificate_unknown
evError: eventId=1041472274774840148 severity=error vendor=Cisco
originator:
hostId: sensor2
appName: cidwebserver
appInstanceId: 351
time: 2003/01/07 04:41:45 2003/01/07 04:41:45 UTC
errorMessage: name=errTransport WebSession::sessionTask(6) TLS connection exce
ption: handshake incomplete.
The feed continues showing all events until you press Ctrl-C.
Step 3
Display the block requests beginning at 10:00 a.m. on February 9, 2005:
sensor#@ show events NAC 10:00:00 Feb 9 2005
evShunRqst: eventId=1106837332219222281 vendor=Cisco
originator:
deviceName: Sensor1
appName: NetworkAccessControllerApp
appInstance: 654
time: 2005/02/09 10:33:31 2004/08/09 13:13:31
shunInfo:
host: connectionShun=false
timeoutMinutes: 40
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
C-64
srcAddr: 11.0.0.1
destAddr:
srcPort:
destPort:
protocol: numericType=0 other
Appendix C
Troubleshooting
78-16527-01