CSMars Data Question

Unanswered Question
Sep 18th, 2007


Does anyone know what MARS does with data that does not match a signature.

Thank you,

Joel Friedman

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
pmccubbin Tue, 09/18/2007 - 10:06

MARS stores system messages such as syslogs and SNMP traps generated by reporting devices in its databases. This action occurs even if the event doesn't match a rule condition.

When writing data to its databases MARS uses a First-in First-out (FIFO) approach.

When the storage limit is reached in a particular model of MARS, it wipes out the oldest day of event data. This data is lost if you are not doing archiving.

Hope this helps.


This Discussion