Chapter 10 Configuring the Sensor Using the CLI
Sensor Configuration Tasks
10-52
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
•
minutes—Duration the logging should be active, in minutes (0-60). The
default is 10 minutes.
•
numPackets—Maximum number of packets to log (0-4294967295). The
default is 1000 packets.
•
numBytes—Maximum number of bytes to log (0-4294967295).
Note
These parameters are optional, you do not have to specify all three.
However, if you include more than one parameter, the sensor continues
logging only until the first threshold is reached. For example, if you set
the duration to 5 minutes and the number of packets to 1000, the sensor
stops logging after the 1000th packet is captured, even if only 2 minutes
have passed.
Example:
sensor# iplog 0 10.16.0.0 duration 5
Logging started for group 0, IP address 10.16.0.0, Log ID 137857506
Warning: IP Logging will affect system performance.
The example shows the sensor logging all IP packets for 5 minutes to and from
the IP address 10.16.0.0.
Note
Make note of the Log ID for future reference.
Step 3
Monitor the IP log status by executing the iplog-status command:
sensor# iplog-status
Log ID: 137857506
IP Address: 10.16.0.0
Group: 0
Status: added
Bytes Captured: 0
Packets Captured: 0
Log ID: 137857512
IP Address: 10.16.0.0
Group: 0
Status: completed
Start Time: 1070363599443768000
End Time: 1070363892909384000
Bytes Captured: 30650
Packets Captured: 263
Log ID: 137857513
Summary of Contents for IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Page 4: ......
Page 450: ...Appendix B Troubleshooting ...