Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

CS-MARS NEtflow and Rules Associated With it

Hello All,

Does anyone know which rules in CS-MARS or Which Rule group is associated with Netflow. i.e. which rule or rules will trigger an incident when a Netflow Event is detected?

1 REPLY
Gold

Re: CS-MARS NEtflow and Rules Associated With it

FWIW, there's a new MARS group here:

http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&forum=MARS&topic=Discussions

I can't say that I know them all, but I think this is the main one:

netflow events get mapped to the "Built/teardown/permitted IP connection" event type, which in turn is part of the "Info/AllSession" event type group. Look for the event type and the event type group in inspection rules to find out where they apply.

134
Views
0
Helpful
1
Replies