Cisco CS-MARS-20-K9 - Security MARS 20 User Manual page 43

Security mars local controller
Table of Contents

Advertisement

Chapter 1
STM Task Flow Overview
Task
Monitor system and network health.
6.
The STM system is more than your MARS Appliance; it includes all reporting devices and mitigation devices
and any MARS Appliances. When assessing the health of the system, you should monitor the health of each of
these devices. You can monitor your system health by using inspection rules that generate notifications for
anomalous behavior, by generating system health queries and reports, and by manually reviewing the system logs
of MARS.
MARS provides reports about use of common resources, including CPU, bandwidth, and memory. To simplify
the monitoring of system health, you can define a report group that organizes these reports into a meaningful
collection. You can also restrict the presentation of those reports and queries to specific user roles.
Because reports can be scheduled, you can notify the appropriate users each time the report is updated.
If you cannot view the resource usage of a reporting device, verify that you have enabled the Monitor
Tip
Resource Usage option as part of that device definition in Admin > System Configuration > Security and
Monitored Devices. For the list of devices that can be configured to provide this data, see
Resource Usage Data, page
MARS also includes detailed logs about the status of the appliance itself, as well as several command-line
utilities that present status on the health of the appliance.
Result: The users responsible for monitoring the system and network health understand the tools and reports
provided by MARS to perform these functions.
For more information, see:
Rule and Report Groups, page 21-24
Rule and Report Group Overview, page 21-25
Configuring Resource Usage Data, page 2-41
pnstatus, page A-39
pnlog, page A-30
Setting Runtime Logging Levels, page 24-1
Viewing the MARS Backend Log Files, page 24-2
Viewing the Audit Trail, page 24-3
Retrieving Raw Messages, page 24-3
78-17020-01
2-41.
User Guide for Cisco Security MARS Local Controller
Checklist for Monitoring Phase
Configuring
1-15

Advertisement

Table of Contents
loading

This manual is also suitable for:

Mars 20Mars 50Mars 100Mars 200

Table of Contents