Cisco IPS-4255-K9 Installation Guide - Page 308

SensorApp and Alerting, SensorApp Not Running

Page 308 highlights

Troubleshooting the Appliance Chapter A Troubleshooting Step 3 Step 4 Total Packets Transmitted = 219260 Total Bytes Transmitted = 103668610 Total Transmit Errors = 0 Total Transmit FIFO Overruns = 0 sensor# If the output says the command and control interface link status is down, there is a hardware issue or an IP address conflict. Make sure the sensor cabling is correct. Make sure the IP address is correct. For More Information • To make sure the sensor cabling is correct, refer to the chapter for your sensor in this document. • For the procedure for making sure the IP address is correct, refer to Configuring Network Settings . SensorApp and Alerting This section helps you troubleshoot issues with SensorApp and alerting. It contains the following topics: • SensorApp Not Running, page A-30 • Physical Connectivity, SPAN, or VACL Port Issue, page A-32 • Unable to See Alerts, page A-33 • Sensor Not Seeing Packets, page A-35 • Cleaning Up a Corrupted SensorApp Configuration, page A-37 SensorApp Not Running The sensing process, SensorApp, should always be running. If it is not, you do not receive any alerts. SensorApp is part of Analysis Engine, so you must make sure the Analysis Engine is running. To make sure Analysis Engine is running, follow these steps: Step 1 Step 2 Log in to the CLI. Determine the status of the Analysis Engine service. sensor# show version Application Partition: Cisco Intrusion Prevention System, Version 7.0(1)E3 Host: Realm Keys key1.0 Signature Definition: Signature Update S329.0 2008-04-16 Virus Update V1.2 2005-11-24 OS Version: 2.4.30-IDS-smp-bigphys Platform: ASA-SSM-20 Serial Number: JAB0948035P License expired: 11-Apr-2008 UTC Sensor up-time is 7 days. Using 1018015744 out of 2093600768 bytes of available memory (48% usage) A-30 Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.0 OL-18504-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412

A-30
Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.0
OL-18504-01
Chapter A
Troubleshooting
Troubleshooting the Appliance
Total Packets Transmitted = 219260
Total Bytes Transmitted = 103668610
Total Transmit Errors = 0
Total Transmit FIFO Overruns = 0
sensor#
If the output says the command and control interface link status is down, there is a hardware issue or an
IP address conflict.
Step 3
Make sure the sensor cabling is correct.
Step 4
Make sure the IP address is correct.
For More Information
To make sure the sensor cabling is correct, refer to the chapter for your sensor in this document.
For the procedure for making sure the IP address is correct, refer to
Configuring Network Settings
.
SensorApp and Alerting
This section helps you troubleshoot issues with SensorApp and alerting. It contains the following topics:
SensorApp Not Running, page A-30
Physical Connectivity, SPAN, or VACL Port Issue, page A-32
Unable to See Alerts, page A-33
Sensor Not Seeing Packets, page A-35
Cleaning Up a Corrupted SensorApp Configuration, page A-37
SensorApp Not Running
The sensing process, SensorApp, should always be running. If it is not, you do not receive any alerts.
SensorApp is part of Analysis Engine, so you must make sure the Analysis Engine is running. To make
sure Analysis Engine is running, follow these steps:
Step 1
Log in to the CLI.
Step 2
Determine the status of the Analysis Engine service.
sensor#
show version
Application Partition:
Cisco Intrusion Prevention System, Version 7.0(1)E3
Host:
Realm Keys
key1.0
Signature Definition:
Signature Update
S329.0
2008-04-16
Virus Update
V1.2
2005-11-24
OS Version:
2.4.30-IDS-smp-bigphys
Platform:
ASA-SSM-20
Serial Number:
JAB0948035P
License expired:
11-Apr-2008 UTC
Sensor up-time is 7 days.
Using 1018015744 out of 2093600768 bytes of available memory (48% usage)