Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

CS-Mars to analyze log

My network has Forescout, Checkpoint Provider-1, FWSM, IDSM-2. Now, I want to use CS-Mars to anylyze log for all devices. CS-Mars can do or not ? Please answer me.

I want to use 1 device to analyze log of all devices in my network.

Thank you for your answer.

2 REPLIES
New Member

Re: CS-Mars to analyze log

hi,

you can integrate FWSM, IDSM-2 and Check-Point into the MARS by using description in the manual. i did this many times for these devices and it works fine.

i've never heared about forescout. is it possible to make forescout send syslogs (or snmp-traps) after the occurance of an event?

if yes, there would be the possibility to use custom parsers to get the box supported from the mars (at least some basic functions).

i can't appreciate how much effort it takes to create custom parsers for the forescout solution. the effort depends on how many different "messages" (syslogs or traps) the forescout sends to the MARS (you have to create a parser for each message itself).

kind regards,

New Member

Re: CS-Mars to analyze log

Thank you for your answer. If you know about the other programs to analyze log, you can talk to me. I search a tool to analyze log in my company.

127
Views
4
Helpful
2
Replies