Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Retrive IP from Raw Messages

Hi All,

We are monitoring a MARS which running V 6.0, recently the MARS is getting much events form the Unknown reporting IPs. I tried to get the IPs of the Unknown reporting devices in many ways, but no luck. The only way I got those IP from the Raw logs of the events, but those are quite huge. I am getting the events comprising 150 pages for just 10 minutes time frame. Is there any possibilities that I can get only the list of IPs of the unknown reporting devices, Thanks in advance for your help....

2 REPLIES
Cisco Employee

Re: Retrive IP from Raw Messages

Unfortunately, there is not a method for listing just the IP address of the unknown reporting devices.

You should be able to run a query with a result format of "Unknown Event Report...".  Limit the device to "Unknown Reporting Device".

The resulting data will include the raw messages, which as you noted includes the unknown reporting IP as well as a button to add this device.  Clicking the "Add Device" button will open a new window with the panel for adding a new security and monitoring device.  You can then define the correct device specifics and add the device so it is correctly parsed and monitored by CS-MARS.  This will be long process based on the amount of data you indicated, but adding one or two devices a day will lower the unknown reporting device events and slowly bring it under control.

Scott

New Member

Re: Retrive IP from Raw Messages

Thanks Scott....

308
Views
0
Helpful
2
Replies