B-67
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Appendix B Troubleshooting
Gathering Information
This section contains these topics:
•
Sensor Events, page B-67
•
show events Command, page B-67
•
Displaying and Clearing Events, page B-68
•
show events Command Output, page B-69
Sensor Events
There are five types of events:
•
evAlert—Intrusion detection alerts
•
evError—Application errors
•
evStatus—Status changes, such as an IP log being created
•
evLogTransaction—Record of control transactions processed by each sensor
application
•
evShunRqst—Block requests
Events remain in the EventStore until they are overwritten by newer events.
show events Command
The show events command is useful for troubleshooting event capture issues in
which you are not seeing events in IDS Event Viewer or Security Monitor. You
can use the show events command to determine which events are being generated
on the sensor to make sure events are being generated and that the fault lies with
the monitoring side.
You can clear all events from EventStore by using the clear events command.
Here are the parameters for the show events command:
sensor# show events
<cr>
alert Display local system alerts
error Display error events
hh:mm[:ss] Display start time
log Display log events
Summary of Contents for IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Page 4: ......
Page 450: ...Appendix B Troubleshooting ...