12-8
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter12 C onfiguring IP Logging
Copying IP Log Files to Be Viewed
Packets Captured: 1039438
Log ID: 2342
IP Address: 192.0.2.2
Virtual Sensor: vs0
Status: completed
Event ID: 209348
Start Time: 2003/07/30 18:24:18 2002/07/30 12:24:18 CST
End Time: 2003/07/30 18:34:18 2002/07/30 12:34:18 CST
sensor#
Step 3
Copy the IP log to your FTP or SCP server.
sensor# copy iplog 2342 ftp://root@209.165.200.225/user/iplog1
Password: ******** Connected to 209.165.200.225 (209.165.200.225). 220 linux.machine.com
FTP server (Version wu-2.6.0(1) Mon Feb 28 10:30 :36 EST 2000) ready. ftp> user (username)
root 331 Password required for root. Password:230 User root logged in. ftp> 200 Type set
to I. ftp> put iplog.8518.tmp iplog1 local: iplog.8518.tmp remote: iplog1 227 Entering
Passive Mode (2,4,6,8,179,125) 150 Opening BINARY mode data connection for iplog1. 226
Transfer complete. 30650 bytes sent in 0.00246 secs (1.2e+04 Kbytes/sec) ftp>
Step 4
Open the IP log using a sniffer program such as Wireshark or TCPDUMP. For more information on
Wiresha rk, go to http://www.wireshark.org. For more information on TCPDUMP, go to
http://www.tcpdump.org/.