8-32
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter8 Configuring Event Action Rules
Configuring General Settings
The following options apply:
virtual-sensor—(Optional) Specifies the learned addresses of the virtual sensor that should be
displayed or cleared.
ip-address—(Optional) Specifies the IP address to query or clear. The sensor displays or clears the
OS ID mapped to the specified IP address.
Displaying and Clearing OS Identifications
To display and clear OS IDs, follow these steps:
Step 1
Log in to the CLI using an account with administrator or operator privileges.
Note
An account with viewer privileges can display OS IDs.
Step 2
Display the learned OS IDs associated with a specific IP address.
sensor# show os-identification learned 192.0.2.0
Virtual Sensor vs0:
10.1.1.12 windows
sensor# show os-identification learned
Virtual Sensor vs0:
10.1.1.12 windows
Virtual Sensor vs1:
10.1.0.1 unix
10.1.0.2 windows
10.1.0.3 windows
sensor#
Step 3
Clear the learned OS IDs for a specific IP address on all virtual sensors.
sensor# clear os-identification learned 192.0.2.0
Step 4
Verify that the OS IDs have been cleared.
sensor# show statistics os-identification
Statistics for Virtual Sensor vs0
OS Identification
Configured
Imported
Learned
Statistics for Virtual Sensor vs1
OS Identification
Configured
Imported
Learned
sensor#
Configuring General Settings
This section describes the general settings, and contains the following topics:
Understanding Event Action Summarization, page 8-33
Understanding Event Action Aggregation, page 8-33