Cisco CS-MARS-20-K9 - Security MARS 20 User Manual page 41

Security mars local controller
Table of Contents

Advertisement

Chapter 1
STM Task Flow Overview
Task
Define custom queries and reports.
4.
Queries and reports are forensic analysis tools. They help you analyze historical data and enable you to identify
trends over longer periods of time than the real-time monitoring features of MARS. The relationship between
queries and reports is essentially that queries are on-demand, refined inspections of data as defined by a report
template. Reports are scheduled to run periodically, enabling you to define the periods and frequencies that you
want to inspect on an ongoing basis. Queries allow you to narrow or broaden your search based on a report
template by filtering the search criteria. WhileMARS provides many predefined report templates, you can define
new report templates that focus on the incidents and events important to fulfilling your policies. This feature can
be especially useful for adhering to compliance reporting requirements, as you can define a report, schedule it to
be generated, and store the results as part of your audit records.
As with overall access, you can restrict the ability to run or view reports and queries based on user role. Such
safeguards can reduce accidental tampering with schedule reports by other users of the system.In addition, you
can configure your report templates so that users are notified of the report. Typically, e-mail is the primary
method used for report notification, but all notification methods are supported.
Result: The report templates required to realize your forensic analysis and audit goals are defined and assigned
to user roles according to your least privilege policies. Any report groups that facilitate access or division of
reports and queries among your staff are defined.
For more information, see:
Queries and Reports, page 20-1
Queries, page 20-1
Perform a Batch Query, page 20-20
Reports, page 20-23
Creating a Report, page 20-25
78-17020-01
User Guide for Cisco Security MARS Local Controller
Checklist for Monitoring Phase
1-13

Advertisement

Table of Contents
loading

This manual is also suitable for:

Mars 20Mars 50Mars 100Mars 200

Table of Contents