cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
232
Views
5
Helpful
1
Replies

CSMars Data Question

jfriedman
Level 1
Level 1

Hi,

Does anyone know what MARS does with data that does not match a signature.

Thank you,

Joel Friedman

1 Reply 1

pmccubbin
Level 5
Level 5

MARS stores system messages such as syslogs and SNMP traps generated by reporting devices in its databases. This action occurs even if the event doesn't match a rule condition.

When writing data to its databases MARS uses a First-in First-out (FIFO) approach.

When the storage limit is reached in a particular model of MARS, it wipes out the oldest day of event data. This data is lost if you are not doing archiving.

Hope this helps.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: