Saving The Query; Viewing Events In Real-Time; Restrictions For Real-Time Event Viewer - Cisco CS-MARS-20-K9 - Security MARS 20 User Manual

Security mars local controller
Table of Contents

Advertisement

Chapter 20
Queries and Reports

Saving the Query

You can save query criteria to re-use as reports or rules.
To save a query as a report
This takes the query that you are using and creates a report. For more information on creating reports,
see
To save a query as a rule
This takes the query to the rules page, populating the rules with the selected query criteria. Likely, you
must identify additional criteria to complete the rule. For more information on creating rules, see
page

Viewing Events in Real-time

The Real-time Event viewer is a query option that permits you to view real-time events as follows:
The real-time events display as a continuously scrolling screen. You can configure query criteria to filter
what is displayed. When viewing raw events, sessionization is not impeded, all the parsed raw events are
sessionized per normal MARS operation. MARS.
The Real-time Event viewer is available for the following query result formats that support ranking by
time (Order/Rank field set to Time):

Restrictions for Real-time Event Viewer

Real-time event queries should be made only from a browser instance that was used to login to MARS.
The real-time query will not have reliable results if it is executed from a browser instance spawned from
the original login instance (for example, a new browser window launched with Ctrl+N, File>New>New
Window, or right-click {link on MARS interface}>Open in New Window).
Multiple real-time queries can operate in multiple browser instances at the same time, but you must login
to MARS with each browser instance.
78-17020-01
Reports, page
20-23.
21-1.
View raw events as they stream to MARS before they are sessionized, with a maximum 5-second
delay
View a sessionized event stream—more delay is possible when there are many events in a session
Matched Incident Ranking
All Matching Sessions
All Matching Sessions, Custom Columns
All Matching Events
All Matching Event Raw Messages
NAT Connection Report
MAC Addresses Report
Unknown Event Report
Detailed NAC Report
User Guide for Cisco Security MARS Local Controller
Viewing Events in Real-time
Rules,
20-13

Advertisement

Table of Contents
loading

This manual is also suitable for:

Mars 20Mars 50Mars 100Mars 200

Table of Contents