Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Cs-Mars Problem

Im working on Cs-Mars version 6.0. after setting some drop rules to avoid having incidents on the dashboard. i figure out that incident are not matching the drop rule even if the incident details are exactly in the scope of the drop rule. is there any where to look to see how Cs-mars parse and treat the events as they gets to incidents ??

1 REPLY
Bronze

Re: Cs-Mars Problem

Drop rules allow false positive tuning on a MARS, and are defined only on the Local Controller Drop Rules page. They allow you to refine the inspected event stream by specifying events and streams to be ignored and whether those data should be stored in the database or discarded entirely. Drop rules are applied to events as they come in from a reporting device, after they have been parsed and before they have been sessionized. Events that match active drop rules are not used to construct incidents. Because the Global Controller does not receive events from reporting devices, rather it receives them from Local Controllers, you cannot define drop rules for the Global Controller.

To display incidents that occur from the firing of rules in a specific rule group:

http://www.cisco.com/en/US/docs/security/security_management/cs-mars/6.0/user/guide/combo/rules.html#wp533079

121
Views
0
Helpful
1
Replies