Clearing Events; Ciddump Script - Cisco IPS-4255-K9 - Intrusion Protection Sys 4255 Installation Manual

Intrusion prevention system appliance and module installation guide for ips 7.0
Table of Contents

Advertisement

Gathering Information
syslogMessage:

Clearing Events

Use the clear events command to clear Event Store. To clear events from Event Store, follow these steps:
Log in to the CLI using an account with administrator privileges.
Step 1
Clear Event Store.
Step 2
sensor# clear events
Warning: Executing this command will remove all events currently stored in the event
store.
Continue with clear? []:
Enter
Step 3

cidDump Script

If you do not have access to IDM, IME, or the CLI, you can run the underlying script cidDump from the
Service account by logging in as root and running /usr/cids/idsRoot/bin/cidDump. The path of the
cidDump file is /usr/cids/idsRoot/htdocs/private/cidDump.html.
cidDump is a script that captures a large amount of information including the IPS processes list, log files,
OS information, directory listings, package information, and configuration files.
To run the cidDump script, follow these steps:
Step 1
Log in to the sensor Service account.
to
Step 2
Su
Enter the following command.
Step 3
/usr/cids/idsRoot/bin/cidDump
Enter the following command to compress the resulting /usr/cids/idsRoot/log/cidDump.html file.
Step 4
gzip /usr/cids/idsRoot/log/cidDump.html
Send the resulting HTML file to TAC or the IPS developers in case of a problem.
Step 5
For More Information
For the procedure for putting a file on the Cisco FTP site, see
Cisco FTP Site, page
Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.0
A-92
description: session opened for user cisco by cisco(uid=0)
to clear the events.
yes
using the Service account password.
root
A-93.
Chapter A
Uploading and Accessing Files on the
Troubleshooting
OL-18504-01

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents