10-53
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Chapter 10 Configuring the Sensor Using the CLI
Sensor Configuration Tasks
IP Address: 10.16.0.0
Group: 0
Status: completed
Start Time: 1070438601052865000
End Time: 1070439201267043000
Bytes Captured: 5104
Packets Captured: 46
Automatic IP Logging for a Specific Signature
You can assign IP logging as an event for the EventAction of a signature so that
every time the signature fires, IP packets are captured for that signature. To turn
off automatic IP logging for a signature, use the default keyword (see Step 8). To
copy and view an IP log file, see
Copying IP Log Files to Be Viewed, page 10-56
.
To automatically log IP packets for a specific signature, follow these steps:
Step 1
Log in to the CLI using an account with administrator or operator privileges.
Step 2
Enter configuration mode:
sensor# configure terminal
Step 3
Enter virtual sensor configuration mode:
sensor(config)# service virtual-sensor-configuration virtualSensor
Step 4
Enter tune micro-engines submode:
sensor(config-vsc)# tune-micro-engines
Step 5
Type the name of the signature engine that you want to tune.
Note
You can view a list of all signature engines by typing a question mark (?)
at the
sensor(config-vsc-virtualSensor)#
prompt.
For example, to tune a simple UDP packet alarm, type the following command:
sensor(config-vsc-virtualSensor)# ATOMIC.UDP
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...