B-69
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Appendix B Troubleshooting
Gathering Information
Note
Time is specified in 24-hour format. You can use single digit numbers for
the date.
Events from the specified time are displayed.
Step 4
Show events that began in the past:
sensor# show events past
hh:mm:ss
The following example displays all events beginning 30 seconds in the past.
sensor# show events past 00:00:30
Step 5
Delete events from the event store:
sensor# clear events
Warning: Executing this command will remove all events currently
stored in the event store.
Continue with clear? :
Step 6
Type yes to clear all events from the EventStore.
show events Command Output
The following is an example of the show events command output:
sensor# show events
evAlert: eventId=1080048367680474106 severity=informational
originator:
hostId: sensor
appName: sensorApp
appInstanceId: 1102
time: 2004/06/24 13:21:33 2004/06/24 13:21:33 EST
interfaceGroup: 0
vlan: 0
signature: sigId=7102 sigName=Reply-to-Broadcast subSigId=0
version=S37
participants:
attack:
attacker: proxy=false
addr: locality=OUT 10.89.146.24
victim:
addr: locality=OUT 10.89.146.24
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...