Gathering Information
NAC—Displays ARC (block) requests.
•
Note
status—Displays status events.
•
past—Displays events starting in the past for the specified hours, minutes, and seconds.
•
hh:mm:ss—Hours, minutes, and seconds in the past to begin the display.
•
The show events command continues to display events until a specified event is available. To exit, press
Note
Ctrl-C.
To display events from Event Store, follow these steps:
Log in to the CLI.
Step 1
Display all events starting now.
Step 2
sensor#@ show events
evError: eventId=1041472274774840147 severity=warning vendor=Cisco
originator:
hostId: sensor2
appName: cidwebserver
appInstanceId: 12075
time: 2008/01/07 04:41:45 2008/01/07 04:41:45 UTC
errorMessage: name=errWarning received fatal alert: certificate_unknown
evError: eventId=1041472274774840148 severity=error vendor=Cisco
originator:
hostId: sensor2
appName: cidwebserver
appInstanceId: 351
time: 2008/01/07 04:41:45 2008/01/07 04:41:45 UTC
errorMessage: name=errTransport WebSession::sessionTask(6) TLS connection exce
ption: handshake incomplete.
The feed continues showing all events until you press Ctrl-C.
Display the block requests beginning at 10:00 a.m. on February 9, 2008.
Step 3
sensor# show events NAC 10:00:00 Feb 9 2008
evShunRqst: eventId=1106837332219222281 vendor=Cisco
originator:
deviceName: Sensor1
appName: NetworkAccessControllerApp
appInstance: 654
time: 2008/02/09 10:33:31 2008/08/09 13:13:31
shunInfo:
host: connectionShun=false
timeoutMinutes: 40
evAlertRef: hostId=esendHost 123456789012345678
sensor#
Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.0
A-90
ARC is formerly known as NAC. This name change has not been completely implemented
throughout IDM, IME, and the CLI for Cisco IPS 7.0.
srcAddr: 11.0.0.1
destAddr:
srcPort:
destPort:
protocol: numericType=0 other
Chapter A
Troubleshooting
OL-18504-01