09-26-2007 06:42 AM - edited 03-09-2019 06:54 PM
Hi, I need to import a raw syslog file of a device generated a few days before CS-MARS installation: how to ?
thank you in advance
09-26-2007 12:25 PM
This is the first time I have heard this request.
I don't think it can be done.
Among other things the time and date would be for events which happened prior to the creation of the database in MARS.
09-26-2007 11:29 PM
The request come from the replacement of cs-mars 50 with cs-mars 110R.
I can export syslog raw file from 50 model and I need to import to the new 110R (5.2 s.o. version)
09-27-2007 06:46 AM
Paul's right, it can't be done...at least not without some other application to read in the file and re-send the syslogs. It wouldn't serve much use anyway, last I checked MARS timestamped most events based on when they were received so the data would be all wrong. You might take a look at the 4.3.1 which was just released, it contains some sort of functionality to move data from the old hardware to the new.
http://www.cisco.com/univercd/cc/td/doc/product/vpn/ciscosec/mars/4_3/rn431.pdf
09-28-2007 06:36 AM
My only thought is that if you are trying to get the historical data into MARS for trend analysis, you can use a Python script to concatenate the current Archived files from the new MARS and an external connector to the location of the old MARS content which I assume is in a flat file.
You could also use a script to combine the two in a SQL database.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: