Enable Snare On The Microsoft Windows Host; Pull Method: Configure The Microsoft Windows Host - Cisco CS-MARS-20-K9 - Security MARS 20 User Manual

Security mars local controller
Table of Contents

Advertisement

Microsoft Windows Hosts
SNARE is installed and started on the local host. A dialog box appears, prompting you to specify
Step 9
whether to allow SNARE to control the EventLog configuration for the Microsoft Windows host.
Select Yes to enable SNARE to control the EventLog configuration for this Microsoft Windows host.
Step 10
The SNARE - Remote Event Logging for Windows user interface appears.
To configure the Snare agent, continue with
Step 11

Enable SNARE on the Microsoft Windows Host

Once you have downloaded and installed the SNARE agent on the target Microsoft Windows host, you
must configure the agent to forward the correct event data in the correct format to the MARS Appliance.
To configure the SNARE agent, follow these steps:
Click All Programs > InterSect Alliance > Snare for Windows to run the SNARE - Remote Event
Step 1
Logging for Windows user interface.
Click Setup > Network Configuration....
Step 2
The Network Configuration page appears.
Specify values for the following fields:
Step 3
Verify that the following options are selected:
Step 4
Note
Click Apply the Latest Audit Configuration on the Network Configuration page.
Step 5
Click File > Close to close SNARE - Remote Event Logging for Windows user interface.
Step 6
The SNARE agent is stopped and restarted to pick up the configuration changes.

Pull Method: Configure the Microsoft Windows Host

As an alternative to the push method, you can configure MARS to pull event log data (security,
application, and system event logs) from Microsoft Windows hosts. The pull method requires the
following steps:
1.
User Guide for Cisco Security MARS Local Controller
10-6
Override detected DNS Name with. Specify the IP address or DNS name of the local host in the
field.
Destination Snare Server address. Specify the IP address or the DNS name of the MARS
Appliance.
Allow SNARE to automatically set audit configuration
Allow SNARE to automatically set file audit configuration
Enable SYSLOG Header
Verify the syslog port is 514.
Ensure that the Windows host and MARS Appliance clocks are synchronized. It is recommend that
you configure a NTP server for this purpose. For more information, see
page
5-10.
Chapter 10
Configuring Generic, Solaris, Linux, and Windows Application Hosts
Enable SNARE on the Microsoft Windows Host, page
10-6.
Specify the Time Settings,
78-17020-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

Mars 20Mars 50Mars 100Mars 200

Table of Contents