Export logs events to another host

Hello

I'm looking to export-> Firesight events connection to another host.

What would be the best way to do this? I can't find any clear option in the GUI to export information.

This information is in mysql or it is in a text file in the clear on the Sourcefirehost which can be copied to another host?

Or if we can configure the Sourcefire to send syslog for each event of connection to another host to syslog?

We want to save the information for 3months + but unfortunately atm journal is about 24 hours.

Kind regards

Jacob

Hi Jacob, access control strategy has logging option, so if a traffic hit a particular rule in which logging is enabled and it is also set to send logs to Syslog.

You will be able to see all kinds of traffic from users on the Syslog, exploit the or normal traffic,

Mark it as correct if she helped to resolve your query.

Thank you

Ankita

Tags: Cisco Security

Similar Questions

  • Email to transfer to another host

    Hi team,

    Currently, my client wants to move its website (hosting BC) to another host (OVH)

    But he wants to keep the same email address (created with BC) and recorded all of his e-mails.

    Is it possible to transfer emails to another host (or perhaps Export/Import)?

    Thank you very much

    Hello

    They can use the same e-mail addresses, but beware that once the customer deletes records MX of BusinessCatalyst e-mail accounts will be deleted with all emails inside.

    For example, the workflow would be something like this:

    Configure an e-mail client to connect to existing accounts and download e-mail messages for all accounts (via IMAP). Once the synchronization is complete for all accounts, you can proceed.

    1. Delete the record MX in British Colombia. This will remove all e-mail and e-mail accounts
    2. Add the MX record as external and that it points to the external mail service
    3. create inboxes on the foreign service
    4. Configure the email client to connect to the new Inbox and copy the mail, it syncs to new accounts

    Hope this helps,

    Mihai

  • Error when you try to a HA VMotion to another host

    In an emergency, closed due to impending failure, I brought all the hosts and VMS backup.  VCenter shows a host computer with 7 virtual machines and another with 4 virtual machines.  When I checked the charges, they seemed to be equal. Then I try to VMotion virtual machines on another host and I get this error:

    A general error occurred: failed to initialize VMotion dest (vim.fault.AlreadyExists)

    Now, I guess that means I'm trying to move a VM somewhere it is already and that VCenter incorrectly reports the location of the virtual machines.  Am I wrong?  How can I fix this without everything closing?

    -Look directly into the ESX, logging with vi client derctly, if the virtual machine is not on the two registered hosts.

    -Restart the mgmt-vmware on both.

    -Restart the service center of VC Server

    Should work...

    Marcelo Soares

    VMWare Certified Professional 310

    Technical Support Engineer

    Chief Executive Officer of the Linux server

  • Export the database from another pc - problem EXP-00056

    Hi all,

    I have a pc (called PC1) with installed Oracle11gR2. I want to export the database from another pc (called PC2) which is connect with PC1 with a LAN.
    I have connected PC2 to PC1 so:
    $ ssh oracle@IP_of_PC1

    and as the user oracle, I tried export then:
    index of the_user/the_pass exp = y subsidies forced is y = y line is my_dump.dmp log = my_log.log

    but he said to me:
    Export: Release 11.2.0.1.0 - Production on Tue 7 Sep 14:44:13 2010

    Copyright (c) 1982, 2009, Oracle and/or its affiliates. All rights reserved.
    EXP-00056: ORACLE error 1034
    ORA-01034: ORACLE not available
    ORA-27101: shared memory realm does not exist
    Linux-x86_64 error: 2: no such file or directory
    EXP-00005: all authorized logon attempts failed
    EXP-00000: export completed unsuccessfully

    Why it does not work?

    Thank you much in advance.

    Run this and show me where exactly you run

    index italia/italia@dbSID exp = y subsidies forced is y = y line is dump070910italia.dmp

  • Moving files from one event to another in the same library

    When I try to move the file by dragging the clip from one event to another, I get this message that "the file could not be opened because there is no file of this type." I have Final Cut Pro X was last updated.

    I find it interesting since when I imported the raw images from an SD card for Final Cut Pro, I copied all the files in the library. I even played the files and they worked.

    I would be very grateful for any answer I can receive. If worse comes to worse, I can always import the images even once to the appropriate event, because I still images raw on one SD card.

    You can post a screenshot of your browser?

    In addition, what happens when you use the reveal based on the Finder.

  • can I use a structure of the event in another structure of the event

    Hello

    Can use a structure of the event in another structure of the event?

    Thank you

    Viviane

    I would put your waveforms in the registers at offset.  You can then use your structure for the main event to trigger on the Show 1... the value change events and process the data, however you need from there.

  • If my disk defragmentation has been stopped and the computer tells me to check the log events for more details how can I do my accessible Defragmenter again?

    If my disk defragmentation has been stopped and the computer tells me to check the log events for more details how can I do my accessible Defragmenter again?

    Hello

    1. have you made changes on the computer recently?

    Method 1.
    Type these commands in the start menu, run a dialog box:
    Here's how:
    a. Click Start.
    b. in the run box, type the following commands one by one and press to enter.

    regsvr32 dfrgsnap.dll
    regsvr32 dfrgui.dll

    Method 2.
    I. to resolve this problem, follow these steps:
    a. Click Start, run, type % Windir%\Inf, and then click OK.
    b. right-click the dfrg.inf file and then click on install.
    OR
    II. Alternatively, you can reinstall Disk Defragmenter using the following command:
    a. Click Start, run and type that the following command and press ENTER.
    Rundll32.exe setupapi, InstallHinfSection DefaultInstall 132 %windir%\inf\dfrg.inf

    I hope this helps.
  • How to export logs GBA?

    Hi all

    Who can tell me how to export logs into ACS step by step?

    System Administration > Configuration > Connect Configuration > remote log targets.

    then define where you want to go in the targets from a distance

  • How do I send vRealize Orchestrator events to another monitoring tool

    I would like to send the vRealize Orchestrator events to another tool (connector BSM). Can achieve us through the following methods,

    1] send vRealize Orchestrator as interruptions snmp events to the BSM connector

    can [2] I send events directly to the connector by agent.

    Please tell me which is the best approach.

    Official documentation is quite lite: generic SNMP request Workflows

    But, I can confirm that there is a simple workflow 'Send a SNMP trap' as part of the library:

    I even recorded a video as an example of use of workflow that was part of a class that I used to teach a few years ago:

    Execution of workflow and trap to send fail - YouTube

    That should help...

  • How to replicate computer invited to another host

    Hello guys,.

    I have essential kit more license and I have try to run the POS 6 host replication task A to 6 POS to host B, I thought of her guest computer clone of the host A to host B but to HOST B there is nothing.

    He was taken to plan the work to clone the guest computer from one host to another host vmware?

    Thank you

    Kind regards

    Andrew

    Replication of PDV is all about protection against the failure of the POS device.

    Look at the following documentation link, there is a section dedicated to replication

    https://pubs.VMware.com/vSphere-60/topic/com.VMware.ICbase/PDF/VMware-data-protection-Administration-Guide-60.PDF

    now, since you have Essentials Plus license.

    you are also entitled to use vSphere replication, which will give you what you want in terms of copy of the replica of your VM. Please refer following documentation

    https://www.VMware.com/files/PDF/vSphere/VMW-vSPHR-replication-6-0.PDF

  • Bad SEO. There is no difference in HTML export before load on the host?

    Bad SEO. There is no difference in HTML export before load on the host?

    I have a site with more than 350 pages, but only 8 are indexed... It took place from March, 2015.

    Can someone help me?

    See Search engine for Adobe Muse Web sites optimization for help on this topic.

  • Migration to another host fails

    Hello community,

    I wrote a shutdown script, enable hotplug memory and cpu, migrate to another host and start the virtual machine after all done tasks.

    I use the following command to migrate the virtual machine to another host:

    Get-VM-name $strNewVMName | Move-VM-Destination esxhost1

    This command starts the task to migrate the engine shut down vm to esxhost2 to esxhost1

    Once the task is completed, the script starts the virtual machine with the command: Get-VM-name $strNewVMName | Start-VM

    But here's my problem:

    I see in the recent tasks that the VM becomes unsubscribe from the 'new' esxhost1 and resave to esxhost1. The virtual machine starts now on the esxhost1

    It works fine when I migrates the engine shut down vm manually via vCenter but not with my script

    Does anyone have an idea to solve my problem?

    Thanks in advance and Merry Christmas

    It is certainly very strange, I went through your steps manually and came to power on a virtual machine on the new host without problem. You have the installer of DRS? or who sits on the local storage of this host?

  • How to use backups RMAN to restore a RAC database to single instance on another host?

    How to use backups Rman to restore a RAC database to single instance on another host?

    I tried to copy these inline for you:

    ------------




    Backups RMAN disk HowTo restore database RAC to single Instance on another node (Doc ID 415579.1)

    Down

  • How to move a virtual machine to another host ESXi running when HA vCenter is not operational... !

    Hey

    We have a few guests of ESXi running the 5.0.0 original version and some running the latest 5.1 U1 or whatever and the last vCenter to do this too.

    the vCenter server is one of the hosts running 5.0.0 and these do not allow HA either active correctly. The problem is a known bug, and you switch to maintenance mode and do funky stuff on the cli to make it work. However, I just want to spend all my virtual machines off the old 5.0.0. hosts and on the new, as the 'old' will be dismantled. I can do all virtual machines by just when close them down and moving off, but I won't be able to do this in with the vm off vCenter vCenter!

    can I turn off, connect directly to the ESXi host, remove it its inventory (this option exists even on the ESXi host live?) and save it to the new 5.1.0 host U1 and fire?

    vCenter complain or fail when she returns to the top?

    they share all the same warehouses of data, so I need to move the backend.

    thoughts?

    Thank you

    Roger

    HA and vMotion (i.e. live migration) are two different things and are independent of each other, so if vMotion is configured correctly, you should be able to migrate the virtual machines (including the vCenter Server VM) to another host.

    André

  • Copy of complete site. I have a Web site. I would copy the entire site (complete with images) to another directory with a different name. Then, transfer to another hosting server. All ideas

    Copy of complete site. I have a Web site. I would copy the entire site (complete with images) to another directory with a different name. Then, transfer to another hosting server. Any ideas?

    Not sure that you need a different directory.

    If you are working on a local computer, create a new site with all the same settings for local files and change the remote server settings to match the second server.

    This ensures you that there is no difference between the two websites.

Maybe you are looking for