I have a MARS running w/ a few custom reports. I noticed that the custom reports/querys had difference in the data information from the pre-configured reports.
1- Difference - The columns:
Rank -Total Sessions - Average / Minute - Raw Source IP - Hosts
Rank - Count (# of Sessions) - Raw Source IP – Hosts
2- Difference - The data:
I have a huge difference on the data, for instance, I’ve attached the 2 prints of the pre-configured report and a custom query. They both have the same time frame.
Query: Activity: All - Top Sources
Pre-configured: Activity: All - Top Sources
The data reported on the pre-configured report is 10x more than the custom query All the variances are the same, time, destination, source, service etc. Is there a diference on the data collected on the query and custom report to the pre-configured report ?
If i query for the preconfigured "Activity: All - Top Sources", or if i manualy configure it, or if i manualy create a report, the data will be diferente from the pre-configured report.
Nope, I don't have an explanation for the presented data. I would recommend opening a TAC case so we can look at the issue and figure out why the query and the report have different results.
The normal submit-inline query is historical in nature. That is, it digs out of the database events matching your criteria. However, scheduled reports are different. They gather information throughout the period the report is set to retrieve. It does this in real time, so, it is not an historical query. This is why you will see the report finished time is very near the end of the query time range. It already has the data, it just has to finish the report.
In this case, if the query and the scheduled report don't agree, it needs to be looked at. These mechanisms are not the same. I would include the screen shots and the version of MARS when opening the case.
DocumentationCode download linksGoalRequirementLimitationsSupported ISR and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and UCS-E Blades:Step by Step ConfigurationConfigure one of the connectivity options to access the Cisco IMC from the n...
Firepower Threat Defense (NGFWv) on UCS E-series - Transparent Mode in HA
DocumentationCode download linksGoalRequirementLimitationsSupported ISR and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and UCS-E Blades:Step by Step ConfigurationCo...
I am currently unable to specify "crypto keyring" command when configuring VPN connection on my cisco 2901 router.
The following licenses have been activated on my router :