cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
695
Views
5
Helpful
2
Replies

MARS Windows Application Logs

fehamilton
Level 1
Level 1

When I pull Windows Logs, I am not getting application logs, it seems like we are getting the Security logs only. I have 6.02. What causes this, and how do we capture the Application Logs?

2 Replies 2

smahbub
Level 6
Level 6

Once you've prepared the Microsoft Windows host, you must identify that host in MARS and identify whether the push or pull method is being used on that host.

To configure the MARS Appliance to either pull or receive logs, follow the steps in the below URL:

http://www.cisco.com/en/US/docs/security/security_management/cs-mars/5.2/user/guide/local_controller/cfghost.html#wp1160788

Personally, I would recommend the snare agent and push method for handling the Windows logs. By doing this you can filter out which events you want to send from the different Event Logs and avoid sending extraneous events.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: