<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: CISCO Router Forensics</title>
	<atom:link href="http://raffy.ch/blog/2008/11/30/cisco-router-forensics/feed/" rel="self" type="application/rss+xml" />
	<link>http://raffy.ch/blog/2008/11/30/cisco-router-forensics/</link>
	<description>Log visualization and log management as seen by Raffael Marty</description>
	<lastBuildDate>Thu, 26 Jan 2012 07:17:42 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Nico</title>
		<link>http://raffy.ch/blog/2008/11/30/cisco-router-forensics/comment-page-1/#comment-16129</link>
		<dc:creator>Nico</dc:creator>
		<pubDate>Mon, 02 Mar 2009 12:04:06 +0000</pubDate>
		<guid isPermaLink="false">http://raffy.ch/blog/2008/11/30/cisco-router-forensics/#comment-16129</guid>
		<description>Hm, you only realy need 1 command...

show tech

That should spit it all out.....</description>
		<content:encoded><![CDATA[<p>Hm, you only realy need 1 command&#8230;</p>
<p>show tech</p>
<p>That should spit it all out&#8230;..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://raffy.ch/blog/2008/11/30/cisco-router-forensics/comment-page-1/#comment-16011</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Wed, 07 Jan 2009 15:39:39 +0000</pubDate>
		<guid isPermaLink="false">http://raffy.ch/blog/2008/11/30/cisco-router-forensics/#comment-16011</guid>
		<description>Many people still use RANCID to collect information about their routers (me included), which already does all the expect wizardry required. The commands that are run by rancid should be a good starting point. 
On the other hand, you could just pull the files that RANCID stores into Splunk (or go all the way and use Splunk as backend instead of CVS/SVN).</description>
		<content:encoded><![CDATA[<p>Many people still use RANCID to collect information about their routers (me included), which already does all the expect wizardry required. The commands that are run by rancid should be a good starting point.<br />
On the other hand, you could just pull the files that RANCID stores into Splunk (or go all the way and use Splunk as backend instead of CVS/SVN).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike</title>
		<link>http://raffy.ch/blog/2008/11/30/cisco-router-forensics/comment-page-1/#comment-14187</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Wed, 10 Dec 2008 02:49:30 +0000</pubDate>
		<guid isPermaLink="false">http://raffy.ch/blog/2008/11/30/cisco-router-forensics/#comment-14187</guid>
		<description>I&#039;ve found expect to be of more trouble than it&#039;s worth for most scripts anymore, especially something like this.  Assuming that the device has SSH enabled you should be able to run these commands directly without much interactivity (as Expect was designed for.)</description>
		<content:encoded><![CDATA[<p>I&#8217;ve found expect to be of more trouble than it&#8217;s worth for most scripts anymore, especially something like this.  Assuming that the device has SSH enabled you should be able to run these commands directly without much interactivity (as Expect was designed for.)</p>
]]></content:encoded>
	</item>
</channel>
</rss>

