Which type of log is this an example of?

Refer to the exhibit. Which type of log is this an example of?


A. syslog
B. NetFlow log
C. proxy log
D. IDS log

cisco-exams

23 thoughts on “Which type of log is this an example of?

  1. Syslog has the folowing fields in an NMS: Source, Message, Hostname, Timestamp (Device), Severity, Tag, Facility, App Name, Proc Id, Msg Id…. Syslog has ONLY has Destination information in the “Message” there is no field used for that. If Syslog had the “Dest. ” it would always be the same (Syslog server IP). Soo its: D (IDS log)

    1. Hi Janooo

      Kindly share your dumps with me (glori4specials(at)gmail.com)….. please I had to make the @ spelt out so it would be visible.

      Thanks

  2. You also see the 5-tuple in IPS events, NetFlow records, and
    other event data. In fact, on the exam you may need to differentiate
    between a firewall log versus a traditional IPS or IDS event. One
    of the things to remember is that traditional IDS and IPS use
    signatures, so an easy way to differentiate is by looking for a
    signature ID (SigID). If you see a signature ID, then most
    definitely the event is a traditional IPS or IDS event.

      1. That is correct but it is valid when we compare IPS/IDS logs with firewall logs. In the specific case i think that we see a syslog log, because of the severity tab

    1. thank you..because the answer is definately D….I am looking at it that someone may actually say the answer is Netflow Log because of the some of the components of the 5-tuple that the Netflow supports and the like…some can say the severity which all they say is true but everything changes when the SigID comes into play,… you cannot have a SysLog with a SigID or a a Netflow with a SigID which leaves us with the best answer D…

      #ExamTip……when u come across such questions its important you use the art of ELIMINATION….

      Thanks!!!

Leave a Reply

Your email address will not be published. Required fields are marked *


The reCAPTCHA verification period has expired. Please reload the page.