10-29
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Chapter 10 Configuring the Sensor Using the CLI
Sensor Administrative Tasks
The show events command displays the requested event types beginning at the
requested start time. If no start time is entered, the selected events are displayed
beginning at the current time. If no event types are entered, all events are
displayed. Events are displayed as a live feed. You can cancel the live feed by
pressing Ctrl-C.
Note
The show events command waits until a specified event is available. It continues
to wait and display events until you exit by pressing the Ctrl-C.
To display and clear events, follow these steps:
Step 1
Log in to the CLI.
Step 2
Display new events:
sensor# show events
Use the regular expression | include shunInfo to view the shun information,
including source address, for the event.
New events are displayed as they occur.
Step 3
Display events from a specific time:
sensor# show events
hh:mm month day year
For example, show events 14:00 September 2 2002 displays all events since 2:00
p.m. September 2, 2002.
Note
Time is specified in 24-hour format. You can use single digit numbers for
the date.
Events from the specified time are displayed.
Step 4
Display events since a specified time for a specified alert level:
sensor# show events alert
level hh:mm month day year
For example, show events alert high 10:00 September 22 2002 displays all high
severity events since 10:00 a.m. September 22, 2002.
Events from the specified time are displayed.
Step 5
Show events that began in the past:
Summary of Contents for IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Page 4: ......
Page 450: ...Appendix B Troubleshooting ...