Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

CS-Mars Query ?

Running vs. 4.1 ... When I run a query on a specific clients source IP address, I am getting alot of Destination IP of 0.0.0.0 .... is this normal? Is there something I am missing in configuration?

3 REPLIES

Re: CS-Mars Query ?

Hi,

It's normal, as it was generated by the device itself. This is why you see the 0.0.0.0 can either be a source or destination IP.

Same goes to interface up/down for a device where if the device itself is sending log to MARS, you'll see the same 0.0.0.0 appear.

Rgds,

AK

New Member

Re: CS-Mars Query ?

Hi,

It's normal. I guess you're getting information from logon events (authentication failure, Windows 2000 login sucessful, etc) That's because there're some event logs without IP information and traffic used is not IP routed (NetBIOS, p.e.) In this manner, if you look at the raw message you'll see the logon information (username, password, domain controller like reporting device, etc)

It's normal.

Good luck!

New Member

Re: CS-Mars Query ?

Thank you!

97
Views
11
Helpful
3
Replies