Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
New Member

Inactive CS-MARS reporting device

Hi all,

We've added three devices to mars...trying to get familiar before populating it with everything.

Each one logs this: Inactive CS-MARS reporting device on an hourly basis.

One device is a WinXP workstation, snare agent isntalled, one is a sun server and one is a catalyst.

Any idea why we get these?

Thanks,

Bob

4 REPLIES
Gold

Re: Inactive CS-MARS reporting device

Because the devices haven't sent any events. Have you run a query for each device to make sure the devices are reporting correctly? You also might try running the "unknown event report" query (one of the last "result format" options). Did you click "activate" after adding the devices?

New Member

Re: Inactive CS-MARS reporting device

The XP box and Sun box have sent events in the past, say occasionally. The catalyst has never sent anything.

When the inactive reporting device rule gets matched, and the incident shows up, the catalyst is always listed:

The following device has not reported events to MARS in 3600 seconds:

The XP box and sun box are sometimes listed. So, I guess when they're not, it's because they've sent an event within the last hour.

The incident (or rule gets fired) occurs every hour on the hour. Since the catalyst has never sent anything, this rule gets fired every hour with, at the very least, the catalyst listed under reporting devices. If the xp and sun boxes have sent something in that previous hour, then they don't get listed.

Does that sound about right?

Can I tune this as false positive and have it log to DB only?

Any advice that way? I just want to filter out anything messy. I suppose if I had netflow enabled on the catalyst, it would be sending something and this rule wouldn't fire really.

I do click activate after adding devices.

Thanks,

Bob

Silver

Re: Inactive CS-MARS reporting device

This same thing was happening to me. It was because my CS-MARS devices weren't generating traffic every hour. It became annoying after a while, so I created a drop rule to filter out all of the "Inactive" events. Just one way to make it go away...

New Member

Re: Inactive CS-MARS reporting device

Thanks guys,

I'll create a drop rule,

Bob

187
Views
0
Helpful
4
Replies
CreatePlease to create content