Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
New Member

Big Trouble for the CS-MARS

Currently, I have some trouble in CS-MARS, and hope anyone can give me some suggestion.

Recently, we upgrade the IDS from McAfee 4.x -> 5.x.  However, it was not on the support list of the CS-MARS.

The way to solve it was to create a new custom device in the CS-MARS 6.x.  However, there are over 4000 event types need to be associated for the devices.

Therefore, does any easy way to do it?

Thanks for any recommandation.

K

Everyone's tags (3)
1 REPLY
Cisco Employee

Re: Big Trouble for the CS-MARS

K;

  There is no easy/automated method to add those 4,000 custom events to CS-MARS.  It may be possible to lower the number by creating broad matching criteria to summarize multiple different McAfee events into a single CS-MARS event.  You may also want to consider creating event parsers for only those McAfee events that are deemed most critical to your environment.

Scott

614
Views
0
Helpful
1
Replies
CreatePlease to create content