[logs] Cisco IDS and Log Reporting

From: Darin.MARAIS@private
Date: Tue Feb 04 2003 - 08:08:44 PST

  • Next message: Rainer Gerhards: "RE: [logs] RE: NT Event Log and Web Server Attacks"

    hi2all,
    
    We have deployed a Cisco NIDS
    
    The Sensor is configured to send alarms to the a console. That console is
    the product Cisco-works 2000. It has a module installed, vpn security
    management solution, and from this module you are able to enter the
    Monitor>>Event Viewer screen.
    This event viewer is a java application and it is my opinion that this is
    rather a cumbersome interface and is not very friendly when it comes to
    trying to use this data in some report documents, for instants just the task
    of cutting and pasting the data from this IE browser screen becomes
    difficult since the data cannot be selected for copying. You are unable to
    save the data or export it. 
    
    I am quite use to the puresucure console interface offered by demarc.org and
    have been lets say, spoilt, however this does not resolve my problem.
    my question to the list is as follows:
    
    If the product uses a "mysql database", are there other tools on the market
    that allow a more customisable interface. i.e. can something like acid be
    adapted to be the console for a Cisco sensor
     
    Regards
    Darin
    
     
    _______________________________________________
    LogAnalysis mailing list
    LogAnalysisat_private
    http://lists.shmoo.com/mailman/listinfo/loganalysis
    



    This archive was generated by hypermail 2b30 : Tue Feb 04 2003 - 10:23:01 PST