Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Parsing Custom Snort Signatures

I have several snort sensors reporting to MARS. As we update signatures and create custom signatures we get the "unknown device event type". Rather than update the Cisco parser (which will be upgraded each new version of MARS), can I create a custom parser and assign this parser and the default snort parser (provided by Cisco) to the same reporting device? I have tried this, but the new parser seems to be ignored as events still show up as "unknown" even after testing the pattern.

320
Views
0
Helpful
0
Replies