cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
722
Views
0
Helpful
2
Replies

Retrive IP from Raw Messages

v-bharath
Level 1
Level 1

Hi All,

We are monitoring a MARS which running V 6.0, recently the MARS is getting much events form the Unknown reporting IPs. I tried to get the IPs of the Unknown reporting devices in many ways, but no luck. The only way I got those IP from the Raw logs of the events, but those are quite huge. I am getting the events comprising 150 pages for just 10 minutes time frame. Is there any possibilities that I can get only the list of IPs of the unknown reporting devices, Thanks in advance for your help....

2 Replies 2

Scott Fringer
Cisco Employee
Cisco Employee

Unfortunately, there is not a method for listing just the IP address of the unknown reporting devices.

You should be able to run a query with a result format of "Unknown Event Report...".  Limit the device to "Unknown Reporting Device".

The resulting data will include the raw messages, which as you noted includes the unknown reporting IP as well as a button to add this device.  Clicking the "Add Device" button will open a new window with the panel for adding a new security and monitoring device.  You can then define the correct device specifics and add the device so it is correctly parsed and monitored by CS-MARS.  This will be long process based on the amount of data you indicated, but adding one or two devices a day will lower the unknown reporting device events and slowly bring it under control.

Scott

Thanks Scott....