Big Trouble for the CS-MARS

Unanswered Question
Sep 9th, 2010
User Badges:

Currently, I have some trouble in CS-MARS, and hope anyone can give me some suggestion.


Recently, we upgrade the IDS from McAfee 4.x -> 5.x.  However, it was not on the support list of the CS-MARS.


The way to solve it was to create a new custom device in the CS-MARS 6.x.  However, there are over 4000 event types need to be associated for the devices.


Therefore, does any easy way to do it?


Thanks for any recommandation.



K

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Scott Fringer Fri, 09/10/2010 - 03:52
User Badges:
  • Cisco Employee,

K;


  There is no easy/automated method to add those 4,000 custom events to CS-MARS.  It may be possible to lower the number by creating broad matching criteria to summarize multiple different McAfee events into a single CS-MARS event.  You may also want to consider creating event parsers for only those McAfee events that are deemed most critical to your environment.


Scott

Actions

This Discussion

Related Content