Add Parser Log Templates For The Custom Device/Application - Cisco CS-MARS-20-K9 - Security MARS 20 User Manual

Security mars local controller
Table of Contents

Advertisement

Chapter 15
Configuring Custom Devices
Figure 15-2
Choose the Type - Appliance or Software.
Step 4
Enter the Vendor, Model and Version for the Device or Application. (For Example, Cisco PIX 7.0)
Step 5
Click Submit.
Step 6
Figure 15-3

Add Parser Log Templates for the Custom Device/Application

While the raw message for an event does include the header information, MARS removes the header
prior to sending the payload to the custom parser. When writing a parser log template, do not include the
header fields.
78-17020-01
Device Type Definition
Appliance - A hardware device that can send logs to the MARS Appliance
Software - An application running on a host and the host can be configured to send logs to the
MARS Appliance
User Defined Device/Application Type
Adding User Defined Log Parser Templates
User Guide for Cisco Security MARS Local Controller
15-3

Advertisement

Table of Contents
loading

This manual is also suitable for:

Mars 20Mars 50Mars 100Mars 200

Table of Contents