Appendix B Troubleshooting
Gathering Information
B-70
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
alertDetails: Traffic Source: int0 ;
evAlert: eventId=1080048367680474107 severity=informational
originator:
hostId: sensor
appName: sensorApp
appInstanceId: 1102
time: 2004/06/24 13:21:33 2004/06/24 13:21:33 EST
interfaceGroup: 0
vlan: 0
signature: sigId=7102 sigName=Reply-to-Broadcast subSigId=0
version=S37
participants:
attack:
attacker: proxy=false
addr: locality=OUT 10.89.146.24
victim:
addr: locality=OUT 10.89.146.24
alertDetails: Traffic Source: int5 ;
cidDump Script
If you do not have access to IDM or the CLI, you can run the underlying script
cidDump from the service account by logging in as root and running
/usr/cids/idsRoot/bin/cidDump. The cidDump file’s path is
/usr/cids/idsRoot/htdocs/private/cidDump.html.
cidDump is a script that captures a large amount of information including the IDS
processes list, log files, OS information, directory listings, package information,
and configuration files.
To run the cidDump script, follow these steps:
Step 1
Log in to the sensor service account.
Step 2
Su to root using the service account password.
Step 3
Type cidDump /usr/cids/idsRoot/bin/cidDump.
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...