[Issue] Sourcefire/Firesight Syslog to include the result online

Hi guys,.

I have set up an alert to syslog on Firesight Virtual Center of defence, but I can't get the result online for events.

Here is an example of event raw that I received

April 14 01:09:20 XXX XXXX: [primary detection engine (a9d9147e-dd96-11e2-a935-a6cb913df812)] [XXXX] [1:34463:2] 'Attempt to outgoing connection of the TeamViewer APP-DETECT remote administration tool' [Classification: potential Violation of company policy] user: unknown, Application: TeamViewer, Client: Internet Explorer, Protocol App: HTTPInterface infiltration: s1p2, output interface: s1p1, entry Security Zone: external, out of Security Zone: internal, [priority: 1] {TCP} x.x.x.x:51355 -> x.x.x.x:80

Here we could see the snort ID, source, destination, port, but not the result of inline (if it is abandoned or not)

Y at - it anyway to change and include these result inline using syslog.

Thank you

Hello

Yes you are right to change gravity and priority will not make changes.

Check: https://bst.cloudapps.cisco.com/bugsearch/bug/CSCux57517/?reffering_site...

Apparently in 5.4 and 6.0 according to the user guide thus only under the settings will be seen in syslog:

-date and time of the alert generation

-event message

-event data

-ID of the triggering event for the generator

-Snort event trigger ID

-review

Kind regards

Aastha Bhardwaj

Rate if this is useful!

Tags: Cisco Security

Similar Questions

  • Include the results in "Batch report" instead of "report USE".

    Hi all

    I modified the ProcessSetup TS 4.0 reminder to perform a test of the preliminary material before testing 8 DUT using batch processing model. Since this is a reminder, the results are not registered by default, so I store it in a global table of results. Then I copy this table of results into my results MainSequence table.

    The problem is that this means that these preliminary results will be saved for UUT0 (if I use "A thread only" synchronization") or to the DUT (if I use the synchronization of batch processing model). How can I add my ProcessSetup test results to the "Results of the batch" section of the results page rather than the sections "USE results? The test checks the shared material and is thus applied to the DUT. I prefer not repeated it for each USE or make it look like, it applies only to WEAR it first.

    Thank you

    Chris

    Tomahawk,

    Al is correct that is whether you use HTML or ASCII report formats, you can override the ModifyReport... Reminders to get what you want. Unfortunately, with the XML declaration, you can use the ModifyReport... Reminders. In order to accomplish the functionality that you want to see everything and still use the report XML form, you will need to change the BatchReport reminder, as well as the XML style sheet you use.

    TestStand 4.2, we have created tutorials and provided better material for our XML Style sheets. With a little effort, I am convinced that with TestStand 4.2, you would be able to reach your goal.

    I suggest to take a look at customization of Style TestStand sheets of TestStand 4.2 help (available online). Unfortunately, Style XML TestStand 4.0 sheets do not have the same quality of literature as the TestStand 4.2 Style sheets, so you don't will not commented sections in the leaves of Style 4.0 as explained in the help.

    For this particular case, you do not want to change the reminder of BatchReport to store the data that you want to place in your report batch section. Then, you change the section batch report of the Style XML with XPath map appropriate to display these data in the batch report.

  • Syslog. Include the address IP of VTY in each message (the configuration changes)

    Hello guys,.

    I discovered that Huawei has a syslog messages different format when it comes to saving the configuration changes in external syslog, however if in Cisco you use a universal login for many users, it is impossible to know what connected IP address who commands...

    I know, a solution would be to allow all users to use its own login, however, I wanted to know is possible for a Cisco router associate the vty from the payer 'connected command' and include this information in Syslog.

    Here is the example for Huawei:

    %%10SHELL/5/cmd (l): - DevIP = 10.219.3.2 - 2 - task: vt0 ip:10.200.7.138 user: * command: display buffer

    Cisco has kind of understands the final message where says what was the IP address of the VTY, however, this IP address is not present in each message syslog like Huawei.

    68954: 168799: sep 22 14:29:21.839: % PARSER-5-CFGLOG_LOGGEDCMD: user: XXXXX connected command: no connection host 10.200.100.10 transport udp port 515

    68952: 168796: 14:18:25.341 Sep 22: % PARSER-5-CFGLOG_LOGGEDCMD: user: XXXXX connected command: exit

    68953: 168797: sep 22 14:18:26.053: % SYS-5-CONFIG_I: configured from console by XXXXX on vty5 (10.200.7.138)

    Is it possible to do something similar in Cisco

    If you Splunk or another business journal reports server you can correlate these events by building a transaction whenever you see a % SYS-5-CONFIG_I event. I have support for this in my application of networks Cisco for Splunk: https://apps.splunk.com/app/1352/ & https://apps.splunk.com/app/1467/

    Take a look and see what you think.

  • Babylon could not connect to the server to get the results online. Please check your internet connection.

    I installed the toolbar of Babylon and babylon pro. I worked with her. But I can't found the average words in the graphic square. I connect to the internet now.

    Hello

    1. what version of Windows operating system work?

    2. do you get this error message on a particular Web site?

    3. What is the full error message that you receive?

    4 are you not able to use the toolbar to search for Babylon or you are having a problem connecting to Internet Explorer?

    5 have had any changes made on the computer before the show?

    Kindly get back to us with information, so that we can help you better.

  • In the results pane date formats

    I am troubleshooting a data corruption issue, and I need to see year-round in the developer sql results pane. When I issue a select statement on a table dates in the format DD-MON-AA results pane. Is there a way to display dates in the format DD/MM/YYYY.

    Hello

    You who control with tools | Preferences | Database | NLS | Date format. Alternatively, a spreadsheet on your connection, just run

    ALTER session set nls_date_format = "DD/MM/YYYY";

    The alter session actually overrides the preference setting and applies to all spreadsheets shared for the connection and also includes the results of the data object browser tab.

    Kind regards
    Gary Graham
    SQL development team

  • Include the webshop in app magazine / animation question

    Hello

    I have some question regarding:

    (1) online store:

    is it possible to include online shops in an app via Adobe DPS simple editing (or only Professional Edition) magazine? This is the online store I talk to appear in the magazine app: http://www.blooms.de/ShopRubriken/128143.html?UID=7F46330ACD307CB6A9DA366D9D969CEC3CCEC71A 3FC29CAC10E3AA

    I did research on the internet and see how Lakeland did (Adobe Digital Publishing Suite - Marketing-soundproofing). They related to the webshop on the internet what looks like the easiest solution (also better?). But y at - it a good way to include the shop online directly in the app magazine rather than a link to it?

    In my research, I also found this video: Adobe Digital Publishing Suite offers a rich commercial experience immersive for Shop Direct | Digital Publishing suit... It looks like a shop online too, but integrated in the application. How does this solution work?

    And: How do analytical to the store if it is integrated in the magazine app?

    (2) Entertainment:

    I would like to animate text/text boxes in a background image full screen. I read that the animations in PDF format (for a clear text on the application!) are not supported. How can I solve this problem?

    Many thanks in advance,

    Helene

    (1) you can incorporate it via a web overlay, but honestly, it's much less complicated and much more likely to work if you include hyperlinks to your store of Web exists and that the reader to do the purchase in pop up in-app browser.

    (2) it is almost impossible to do it without a bunch of work on board animate. To be honest, I don't really think that it is always worth the time spent. I would look to do a different design instead which is not based on this style of animation.

    Neil

  • How folder names can be included in the results of search for bookmarks?

    I would like to be able to search for names of folder of bookmarks in the Bookmarks window.

    Y at - it a commonly recommended addon which will include the names of the folders in the search results?

    @cor-el, thank you for your reply - I hope there could be a real record search. I'm probably not the first person to need this.

    I see this new extension ("Awesome search Extension") without a lot of users yet - it's not clear to me if it has the feature I need, but maybe it's worth a try?

    https://addons.Mozilla.org/en-us/Firefox/addon/awesome-search-extension/

  • Whenever I have to copy/paste the results include many points of mark boring... are not part of the original text.

    Whenever I have to copy/paste the results include many points of mark boring... are not part of the original text.  I use wordperfect 12 with Windows XP.

    How can I solve this dilemma?

    Hello, Roger Scott,.

    -Does only with WordPerfect or with other applications as well?

    If this only happens with WordPerfect so I suggest you to check with WordPerfect support for more information.

    http://www.Corel.com/Corel/pages/index.jsp?PgId=800034

  • I have upgraded to Windows 10 64 Pro and all my apps Adobe has stopped working; I get the popular "MSVCP110.dll is missing" issue; I uninstalled everything, including the creative cloud, rebooted the PC and installed it back again! Same thing! I tried thi

    I have upgraded to Windows 10 64 Pro and all my apps Adobe has stopped working; I get the popular "MSVCP110.dll is missing" issue; I uninstalled everything, including the creative cloud, rebooted the PC and installed it back again! Same thing! I tried this several times. I'm really stuck! Can someone help with how this is solved; I follow online (two solutions) and tried both; not good! No matter what I do, I get the error! The rest of the applications say they are absent from the other files like this; It seems that there is something to do during the installation that keeps this issue alive!

    Run the command to check the file system once:

    https://support.Microsoft.com/en-in/KB/929833

    Also repair Microsoft Redistributable packages from the control panel > programs and features.

    If not installed, download and install the Visual C++ 2013 package.

    Let me know if you need more assistance.

  • Apparently, I have a missing MSVCP110.dll after going to Windows 10.  The result is that I can't open Flash CC Pro.  All work through this issue?

    Apparently, I have a missing MSVCP110.dll after going to Windows 10.  The result is that I can't open Flash CC Pro.  All work through this issue?

    Error: "msvcp110.dll missing file.

  • Print the results of a quiz with name included

    I've seen this asked several times, but I couldn't find the answer. I'm running 7 Captivate on Windows XP. I just need to print the results of the quiz which will include the student's name. I tried the text box on the certificate widget but if I use the "print" key nothing of what has been added to the certificate (as the name) will be printed. I can do a screen capture and the data is printed, but I was wondering if there is a better way to enter the name of a student and then embed it in the results page. Looks like it would be a "no brainer" feature to have, but I'm not.

    I don't want to capture results electronically. I just need to print the results that will will also show their name.

    I am a new user of Captivate. Any help or pointing me in the direction to learn how to do this would be much appreciated.

    You can get the learner to enter their name in a box of text at the beginning of the module, store this text in a user variable, and then display this text at the end of the lesson on the slide, you print.

  • You want to include spaces in the results in the text field.

    Hi all

    Please help with possible means.
    I want to ge the output of a test classified in the results as such.
    I need to get a < space > then the names.
    for example I want < space > < space > and then test on the ground in my report of responses.
    Currently, when I give ' ' and concat it with the name column it provides two spaces at the beginning.

    Other ways to do it.

    Kind regards
    Bla

    Hi Kim,

    Try this, go to the properties of column-> change-> Dataformat treat text as drop down-> text gross (do not break spaces).
    This will allow spaces.

    Thank you
    Vino

  • Can someone help me interpret the results of a log cbs.log file?

    My laptop worked little strange - gel sometimes and only excessively slow.  I ran chkdsk /f checks and / r.  Both went well.  I then ran sfc/scannow.  The results of this analysis are displayed below.  I'm not a pc expert, so I don't know if I'm all together or if there is something else, I have to do.  Specifically, the last line of the cbs.log file says, "Verify and Repair Transaction completed. All of the files and registry keys listed in the framework of this operation were properly repaired".

    Any help would be appreciated!  Sorry for the text copy/pasted for a long time.  I cut about 99% of the out and about 1% of the folder (due to a limit of 60 000 characters) just left.  I couldn't find a way to attach a file.

    Thank you!

    POQ 64 ends.

    2012-10-09 22:06:25, Info CSI 00000171 [SR] check complete

    2012-10-09 22:06:26, info CSI 00000172 [SR] components check 100 (0 x 0000000000000064)

    2012-10-09 22:06:26, transaction Info CSI 00000173 [SR] beginning verify and repair

    2012-10-09 22:06:37, info CSI 00000174 Member \SystemRoot\WinSxS\amd64_microsoft-windows-sidebar_31bf3856ad364e35_6.0.6002.18005_none_2ce6c04cdc275758\settings.ini file hashes are not actual file [l:24 {12}] "settings.ini": "

    Found: {l:32 b:sKFy6962 + 2YBWdYMZ6Z/UOVMGpEOdEczYmmYd2o9CE4 =} expected: {l:32 = b:v6OQf2AJO5FVbRBJuIwXxkdkCoOaSk3y0ol6uTH491o}

    2012-10-09 22:06:37, info CSI 00000175 [SR] cannot repair the military record [l:24 {12}] "settings.ini" Microsoft-Windows-Sidebar, Version = 6.0.6002.18005, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), the Culture neutral, VersionScope is 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, type neutral, TypeName neutral, neutral to the public key in the store, hash mismatch "

    2012-10-09 22:06:40, info CSI 00000176 Member \SystemRoot\WinSxS\amd64_microsoft-windows-sidebar_31bf3856ad364e35_6.0.6002.18005_none_2ce6c04cdc275758\settings.ini file hashes are not actual file [l:24 {12}] "settings.ini": "

    Found: {l:32 b:sKFy6962 + 2YBWdYMZ6Z/UOVMGpEOdEczYmmYd2o9CE4 =} expected: {l:32 = b:v6OQf2AJO5FVbRBJuIwXxkdkCoOaSk3y0ol6uTH491o}

    2012-10-09 22:06:40, info CSI 00000177 [SR] cannot repair the military record [l:24 {12}] "settings.ini" Microsoft-Windows-Sidebar, Version = 6.0.6002.18005, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), the Culture neutral, VersionScope is 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, type neutral, TypeName neutral, neutral to the public key in the store, hash mismatch "

    2012-10-09 22:06:40, info CSI 00000178 [SR] this element is referenced by [l:162 {81}] "' Package_17_for_KB948465 ~ 31bf3856ad364e35 ~ amd64 ~ ~ 6.0.1.18005.948465 - 60_neutral_GDR" "

    2012-10-09 22:06:41, Info CSI 00000179 repair results created:

    POQ 65 begins:

    2012-10-09 22:17:24, info CSI 00000301 [SR] cannot repair the military record [l:24 {12}] "settings.ini" Microsoft-Windows-Sidebar, Version = 6.0.6002.18005, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), the Culture neutral, VersionScope is 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, type neutral, TypeName neutral, neutral to the public key in the store, hash mismatch "

    2012-10-09 22:17:24, info CSI 00000302 Member \SystemRoot\WinSxS\amd64_microsoft-windows-sidebar_31bf3856ad364e35_6.0.6002.18005_none_2ce6c04cdc275758\settings.ini file hashes are not actual file [l:24 {12}] "settings.ini": "

    Found: {l:32 b:sKFy6962 + 2YBWdYMZ6Z/UOVMGpEOdEczYmmYd2o9CE4 =} expected: {l:32 = b:v6OQf2AJO5FVbRBJuIwXxkdkCoOaSk3y0ol6uTH491o}

    2012-10-09 22:17:24, info CSI 00000303 [SR] cannot repair the military record [l:24 {12}] "settings.ini" Microsoft-Windows-Sidebar, Version = 6.0.6002.18005, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), the Culture neutral, VersionScope is 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, type neutral, TypeName neutral, neutral to the public key in the store, hash mismatch "

    2012-10-09 22:17:24, Info CSI 00000304 [SR] this element is referenced by [l:162 {81}] "' Package_17_for_KB948465 ~ 31bf3856ad364e35 ~ amd64 ~ ~ 6.0.1.18005.948465 - 60_neutral_GDR" "

    2012-10-09 22:17:24, info CSI 00000305 hashes for Member file? \C:\Windows\PolicyDefinitions\inetres.ADMX are not real file [l:24 {12}] "inetres.admx": "

    Found: {l:32 b:DjclSPQ + c3ju7E53XXW47eR94SH7ICruHSUKg8YAkO0 =} expected: {l:32 b:3 T / Xc + 0 k/wBxJ4k/vlPd86jLOYtWOjRsHrz0hHH9H8s =}

    2012-10-09 22:13:42, CSI 0000027e Info [SR] repair corrupted file [ml:520 {260}, l:64 {32}] '------? \C:\windows\policydefinitions"\[l:24{12}]"Inetres.ADMX' of the store

    2012-10-09 22:13:42, CSI Info 0000027f WARNING: file [l:24 {12}] "inetres.admx" in [l:64 {32}] '-? ' "" \C:\windows\policydefinitions' switching property

    Old: Microsoft-Windows-InetRes-Adm, Version = 9.1.8112.16421, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral

    New: Microsoft-Windows-InetRes-Adm, Version = 8.0.6001.18702, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral

    2012-10-09 22:13:44, info CSI 00000280 hashes for Member file? \C:\Windows\PolicyDefinitions\en-US\InetRes.adml are not real file [l:24 {12}] "InetRes.adml": "

    Found: {l:32 b:8uqfOni5TmKQ2 + wymJKX9uLDOmUV2H1RKpYV3gacaRw =} expected: {l:32 = b:f2Ca02GHu2Yr3ccXiLvfpdfLkfeeDX2UExmZb6pQm2U}

    2012-10-09 22:13:44, info CSI 00000281 [SR] repair file corrupted [ml:520 {260}, l:76 {38}] '------? \C:\Windows\PolicyDefinitions\en-us"\[l:24{12}]"InetRes.adml' of the store

    2012-10-09 22:13:44, info CSI 00000282 WARNING: file [l:24 {12}] "InetRes.adml" in [l:76 {38}] '-? ' "" \C:\Windows\PolicyDefinitions\en-us' switching property

    Old: Microsoft-Windows-InetRes - Adm.Resources, Version = 9.1.8112.16421, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10 {5}] 'en-US', VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral

    New: Microsoft-Windows-InetRes - Adm.Resources, Version = 8.0.6001.18702, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture = [l:10 {5}] 'en-US', VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral

    2012-10-09 22:17:25, 00000306 CSI info [SR] repair corrupted file [ml:520 {260}, l:64 {32}] '------? \C:\windows\policydefinitions"\[l:24{12}]"Inetres.ADMX' of the store

    2012-10-09 22:17:25, info CSI 00000307 WARNING: file [l:24 {12}] "inetres.admx" in [l:64 {32}] '-? ' "" \C:\windows\policydefinitions' switching property

    Old: Microsoft-Windows-InetRes-Adm, Version = 9.1.8112.16421, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral

    New: Microsoft-Windows-InetRes-Adm, Version = 8.0.6001.18702, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral

    2012-10-09 22:17:25, info CSI 00000308 hashes for Member file? \C:\Windows\PolicyDefinitions\en-US\InetRes.adml are not real file [l:24 {12}] "InetRes.adml": "

    Found: {l:32 b:8uqfOni5TmKQ2 + wymJKX9uLDOmUV2H1RKpYV3gacaRw =} expected: {l:32 = b:f2Ca02GHu2Yr3ccXiLvfpdfLkfeeDX2UExmZb6pQm2U}

    2012-10-09 22:17:25, 00000309 CSI info [SR] repair corrupted file [ml:520 {260}, l:76 {38}] '------? \C:\Windows\PolicyDefinitions\en-us"\[l:24{12}]"InetRes.adml' of the store

    2012-10-09 22:17:25, CSI Info 0000030a WARNING: file [l:24 {12}] "InetRes.adml" in [l:76 {38}] '-? ' "" \C:\Windows\PolicyDefinitions\en-us' switching property

    Old: Microsoft-Windows-InetRes - Adm.Resources, Version = 9.1.8112.16421, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture = [l:10 {5}] 'en-US', VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral

    New: Microsoft-Windows-InetRes - Adm.Resources, Version = 8.0.6001.18702, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture = [l:10 {5}] 'en-US', VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral

    2012-10-09 22:17:25, created results CSI 0000030b repair Info:

    POQ 127 ends.
    2012-10-09 22:17:25, all repairs [SR] CSI Info 0000030 c
    2012-10-09 22:17:25, CSI Info 0000030 d [SR] validation of transaction
    2012-10-09 22:17:25, transaction CSI Info 0000030e Creating NT (seq 1), objectname [6] "(null) '"
    2012-10-09 22:17:25, CSI Info 0000030f NT created transaction (seq 1) result 0x00000000, manage @0x14c4
    2012-10-09 22:17:25, Info CSI 00000310@2012/10/10:02:17:25.662 CSI perf trace:
    CSIPERF:TXCOMMIT; 143298
    2012-10-09 22:17:25, Info CSI 00000311 [SR] check and complete repair operation. All of the files and registry keys listed in this operation were repaired successfully

    Hello

    As noted at the end of your message SFC/scannow points out that there is no rest
    questions that he can fix.

    More information on how to easily read the important information as SFC/scannow
    adds to the cbs.log.

    Many files that SFC cannot resolve are not important.

    Start - type in the search box-> find CMD in top - click right on - RUN AS ADMIN

    put the command from below (copy and paste) in this box and her and then press ENTER.

    findstr/c: "[SR]" %windir%\logs\cbs\cbs.log > sfcdetails.txt

    who creates the sfcdetails.txt file in the folder that you are in when you run it.

    So if you're in C:\Windows\System32 > then you will need to look in that folder for the file.

    How to analyze the log file entries that the Microsoft Windows Resource Checker (SFC.exe) program
    in Windows Vista
    http://support.Microsoft.com/kb/928228

    This creates sfcdetails.txt in C:\Windows\System32 find and you can post the errors in a message
    here. NOTE: there are probably duplicates so please only post once each section error.

    You can read the newspaper/txt files easier if you right click on Notepad or Wordpad then RUN AS ADMIN - then
    You can navigate to sfcdetails.txt (in C:\Windows\System32) or cbs.log (in C:\Windows\Logs) as needed.
    (You may need to search sfcdetails.txt if it is not created in the default folders.)

    =======================================================

    Troubleshooting:

    Use the startup clean and other methods to try to determine the cause of and eliminate
    the questions.

    ---------------------------------------------------------------

    What antivirus/antispyware/security products do you have on the machine? Be one you have NEVER
    on this machine, including those you have uninstalled (they leave leftovers behind which can cause
    strange problems).

    ----------------------------------------------------

    Follow these steps:

    Start - type this in the search box-> find COMMAND at the top and RIGHT CLICK – RUN AS ADMIN

    Enter this at the command prompt - sfc/scannow

    How to analyze the log file entries that the Microsoft Windows Resource Checker (SFC.exe) program
    generates in Windows Vista cbs.log
    http://support.Microsoft.com/kb/928228

    Also run CheckDisk, so we cannot exclude as much as possible of the corruption.

    How to run the check disk at startup in Vista
    http://www.Vistax64.com/tutorials/67612-check-disk-Chkdsk.html

    ==========================================

    After the foregoing:

    How to troubleshoot a problem by performing a clean boot in Windows Vista
    http://support.Microsoft.com/kb/929135
    How to troubleshoot performance issues in Windows Vista
    http://support.Microsoft.com/kb/950685

    Optimize the performance of Microsoft Windows Vista
    http://support.Microsoft.com/kb/959062
    To see everything that is in charge of startup - wait a few minutes with nothing to do - then right-click
    Taskbar - the Task Manager process - take a look at stored by - Services - this is a quick way
    reference (if you have a small box at the bottom left - show for all users, then check that).

    How to check and change Vista startup programs
    http://www.Vistax64.com/tutorials/79612-startup-programs-enable-disable.html

    A quick check to see that load method 2 is - using MSCONFIG then put a list of
    those here.
    --------------------------------------------------------------------

    Tools that should help you:

    Process Explorer - free - find out which files, key of registry and other objects processes have opened.
    What DLLs they have loaded and more. This exceptionally effective utility will show you even who has
    each process.
    http://TechNet.Microsoft.com/en-us/Sysinternals/bb896653.aspx

    Autoruns - free - see what programs are configured to start automatically when you start your system
    and you log in. Autoruns also shows you the full list of registry and file locations where applications can
    Configure auto-start settings.
    http://TechNet.Microsoft.com/en-us/sysinternals/bb963902.aspx
    Process Monitor - Free - monitor the system files, registry, process, thread and DLL real-time activity.
    http://TechNet.Microsoft.com/en-us/Sysinternals/bb896645.aspx

    There are many excellent free tools from Sysinternals
    http://TechNet.Microsoft.com/en-us/Sysinternals/default.aspx

    -Free - WhatsInStartUP this utility displays the list of all applications that are loaded automatically
    When Windows starts. For each request, the following information is displayed: Type of startup (registry/Startup folder), Command - Line String, the product name, Version of the file, the name of the company;
    Location in the registry or the file system and more. It allows you to easily disable or remove unwanted
    a program that runs in your Windows startup.
    http://www.NirSoft.NET/utils/what_run_in_startup.html

    There are many excellent free tools to NirSoft
    http://www.NirSoft.NET/utils/index.html

    Window Watcher - free - do you know what is running on your computer? Maybe not. The window
    Watcher says it all, reporting of any window created by running programs, if the window
    is visible or not.
    http://www.KarenWare.com/PowerTools/ptwinwatch.asp

    Many excellent free tools and an excellent newsletter at Karenware
    http://www.KarenWare.com/

    ===========================================

    Vista and Windows 7 updated drivers love then here's how update the most important.

    This is my generic how updates of appropriate driver:

    This utility, it is easy see which versions are loaded:

    -Free - DriverView utility displays the list of all device drivers currently loaded on your system.
    For each driver in the list, additional useful information is displayed: load address of the driver,
    Description, version, product name, company that created the driver and more.
    http://www.NirSoft.NET/utils/DriverView.html

    For drivers, visit manufacturer of emergency system and of the manufacturer of the device that are the most common.
    Control Panel - device - Graphics Manager - note the brand and complete model
    your video card - double - tab of the driver - write version information. Now, click on update
    Driver (this can do nothing as MS is far behind the certification of drivers) - then right-click.
    Uninstall - REBOOT it will refresh the driver stack.

    Repeat this for network - card (NIC), Wifi network, sound, mouse, and keyboard if 3rd party
    with their own software and drivers and all other main drivers that you have.

    Now in the system manufacturer (Dell, HP, Toshiba as examples) site (in a restaurant), peripheral
    Site of the manufacturer (Realtek, Intel, Nvidia, ATI, for example) and get their latest versions. (Look for
    BIOS, Chipset and software updates on the site of the manufacturer of the system here.)

    Download - SAVE - go to where you put them - right click - RUN AD ADMIN - REBOOT after
    each installation.

    Always check in the Device Manager - drivers tab to be sure the version you actually install
    presents itself. This is because some restore drivers before the most recent is installed (sound card drivers
    in particular that) so to install a driver - reboot - check that it is installed and repeat as
    necessary.

    Repeat to the manufacturers - BTW in the DO NOT RUN THEIR SCANNER device - check
    manually by model.

    Look at the sites of the manufacturer for drivers - and the manufacturer of the device manually.
    http://pcsupport.about.com/od/driverssupport/HT/driverdlmfgr.htm

    How to install a device driver in Vista Device Manager
    http://www.Vistax64.com/tutorials/193584-Device-Manager-install-driver.html

    If you update the drivers manually, then it's a good idea to disable the facilities of driver under Windows
    Updates, that leaves about Windows updates but it will not install the drivers that will be generally
    older and cause problems. If updates offers a new driver and then HIDE it (right click on it), then
    get new manually if you wish.

    How to disable automatic driver Installation in Windows Vista - drivers
    http://www.AddictiveTips.com/Windows-Tips/how-to-disable-automatic-driver-installation-in-Windows-Vista/
    http://TechNet.Microsoft.com/en-us/library/cc730606 (WS.10) .aspx

    ===========================================

    Refer to these discussions because many more excellent advice however don't forget to check your antivirus
    programs, the main drivers and BIOS update and also solve the problems with the cleanboot method
    first.

    Problems with the overall speed of the system and performance
    http://support.Microsoft.com/GP/slow_windows_performance/en-us

    Performance and Maintenance Tips
    http://social.answers.Microsoft.com/forums/en-us/w7performance/thread/19e5d6c3-BF07-49ac-a2fa-6718c988f125

    Explorer Windows stopped working
    http://social.answers.Microsoft.com/forums/en-us/w7performance/thread/6ab02526-5071-4DCC-895F-d90202bad8b3

    I hope this helps.

    Rob Brown - Microsoft MVP<- profile="" -="" windows="" expert="" -="" consumer="" :="" bicycle=""><- mark="" twain="" said="" it="">

  • Adobe Captivate 7 - is the review of the results of the quiz based on the types of questions?

    Adobe Captivate 7 provides the function that you can review the questions, and you can see which of them have answered correctly and that one of them has responded incorrectly. In my e-learning project, there is an exercise that consists of multiple choice questions and drag and drop tasks. This question / task landslides are among the content slides, this means for example after 5 content slides are a 2 slides, it issues then 3 content slides and slide 1 question and so on. The results of all the types of questions - multiple choice questions, drag and drop - are included in the results of the quiz. At the end of the e-learning the 'quiz' results slide comes with the button "check Quiz." I tested this function after exporting the e-learning of Adobe Captivate7. I noticed the following: If you click on the button "check Quiz" the learner back to all the question slides he or she responded. For that on question slides were automatically placed the buttons 'next' and 'back' and the 'inspection' on the ground it is written what the learner has responded to the two first questions are multiple choice questions. There, it works fine the two buttons will appear. After clicking on the button 'next' on the first question slide that contains a multiple choice question, the learner is the second slide of the question, which also contains a multiple choice question. The third issue is a task of drag / move. He do not appear the buttons so the quiz review stops and there is no field 'inspection '.

    How do I review the quiz works correctly despite types of questions?

    You will need to create the buttons that you want the slide D & D and format them to look like buttons on the other Quiz slides. Then hide them by deselecting "Visible output" in the properties panel.

    For these D & D slides, you will need a conditional action advanced or shared to be triggered on enter. The action will check the value of the system variable cpInReviewMode, which is a Boolean with the value of 1 by Captivate when you're in playback mode. If its value is in fact = 1 show you the hidden buttons. If you group these buttons, you will need only a single command:

    IF cpInReviewMode is equal to 1

    See the Gr_Buttons

    Continue

    ON THE OTHER

    Continue

  • [CS5.5] [JS] delete the character before the result of the search

    Hello

    I have a small question.

    I would like to remove all spaces before any text containing the tag with a specific character style.

    Example: "call: [SPACE] [BEGIN TANK STYLE FRUIT] 5 parts [END TANK STYLE FRUIT]".

    I would like to remove the space...

    A piece of my code:

    app.findTextPreferences = NothingEnum.nothing;

    app.findTextPreferences.appliedCharacterStyle = "FRUIT".

    myResultsList = app.activeDocument.findText ();

    for (var k = myResultsList.length - 1; k >-1; k = k - 1) {}

    How can I remove the space before the result?

    }

    Aynone have an idea?

    Thank you

    John

    Hi J & J,

    I have a little problem with the two scripts here.

    Jarek is obviously going to be very fast, but it assumes there is no local formatting on the words of style FRUIT, i.e. No bold / italic / color / highlight replacements applied to these texts. If this is the case then his script (perhaps with a more original original combination) them IS way to go. If it's not!

    John, I don't understand how the script you found could possibly work.

    There are 2 major bugs with it.

    var myCharacters = myResultsList [k] .parentTextFrames [0] .characters;

    myCharacters.itemByRange(myLocation-1,1).remove ();

    should be replaced by

    var myCharacters is myResultsList [k].parentStory.characters;.

    myCharacters.itemByRange (myLocation-1, myLocation) .remove ();

    To the help of parentTextFrames is not a good idea because it will fail on threaded textframe, give it index the character of possiosion since the beginning of the story and not the beginning of the textframe.

    having itemByRange(myLocation-1,1).remove () will withdraw find it until the second character in the story. I understand that you just want to remove the space before the style!

    This brings to a 3rd problem in your script that removes the (fixed once upwards) any character preceding the style regardless of whether or not it is a space.

    In any case my way would be with one of these 2 functions according to the conditions weather there is always a space before the style of fruits or not.

    It will only remove spaces (no returns or other characters) that precede the style.

    The first function 'removeCharacterBeforeStyle' is the equivalent of your corrected script but better (at least in my humble opinion)

    // http://forums.adobe.com/thread/1213463?tstart=0word.
    // Removes  letter / spaces before a character style
    app.doScript("removeAllSpacesBeforeStyle()", ScriptLanguage.javascript, undefined, UndoModes.ENTIRE_SCRIPT);
    //app.doScript("removeCharacterBeforeStyle()", ScriptLanguage.javascript, undefined, UndoModes.ENTIRE_SCRIPT);
    
    function removeCharacterBeforeStyle() {
        // to delete ANY character that precedes the FRUIT style. short and sweet :-)
        app.findTextPreferences = null;
        app.findTextPreferences.appliedCharacterStyle = "FRUIT";
        var  myFinds =  app.documents[0].findText(),
               l = myFinds.length, pos;
        while (l--)   myFinds[l].parentStory.characters.itemByRange (pos = myFinds[l].insertionPoints[0].index-1, pos++).remove();
    };
    
    function removeAllSpacesBeforeStyle() {
        // This will delete spaces (including hairspaces), tabs etc. but not returns that precedes the FRUIT style
        // see http://www.indiscripts.com/post/2011/09/what-exactly-is-a-word for hairspace and other potential issues
        // not so short and not so sweet :-(
        // but does the job without messing up most of the local overrides of the character style |:-)
        var doc = app.documents[0];
        app.findTextPreferences = app.changeTextPreferences = null;
        app.findTextPreferences.findWhat = "^|"; // this is one way of dealing with hairline spaces (warning their format will get messed up)
        app.changeTextPreferences.changeTo = "^4^4^4^4^3";
        doc.changeText();
        app.findTextPreferences = null;
        app.findTextPreferences.appliedCharacterStyle = "FRUIT";
        var  myFinds = doc.findText(),
               l = myFinds.length,
               ps, find_CharacterInStoryIndex, find_WordInStoryIndex, StartOfGap, EndOfGap;
        app.findTextPreferences = app.findGrepPreferences = app.changeGrepPreferences = null;
        app.findGrepPreferences.findWhat = "((?![\\r\\n])\\s)+"; // find spaces that are not returns about the same as "[~m~>~f~S~s~<~/~.~3~4~%\\x{20}~|\\t]+" I have not compaired the speeds
        while (l--)  {
            ps = myFinds[l].parentStory;
            find_CharacterInStoryIndex = myFinds[l].insertionPoints[0].index-1;
            if ((find_WordInStoryIndex = ps.words.itemByRange(ps.words[0], myFinds[l].words[0]).words.length-2) <0) continue;
            // the 'if' checks that the find is not the first word in the story if it was the ALL the spaces in the whole story would be removed
            StartOfGap = ps.words[find_WordInStoryIndex].insertionPoints[-1].index;
            EndOfGap = ps.words[find_WordInStoryIndex+1].index-1;
            // if the FRUIT style starts at the beginning  of a word remove spaces before that word
            if (find_CharacterInStoryIndex == EndOfGap)  ps.characters.itemByRange(StartOfGap,EndOfGap).changeGrep();
        }
        app.findTextPreferences.findWhat = "^4^4^4^4^3"; // put the hairspaces back
        app.changeTextPreferences.changeTo = "^|";
        doc.changeText();
        app.findTextPreferences  = app.changeTextPreferences = app.findGrepPreferences = null;
    }
    

    Concerning

    Trevor

    P.s. If you do not have hairspaces (and you probably haven't) her you could for aesthetic reasons to remove at least 6 lines of code.

Maybe you are looking for