I have a MARS 50, and i tried to add a Linux to send syslog messages to it. I added it, i can see the linux int the topology window.
I run a nmap scan on the linux, i get a lot of syslog messages on the linux console because of the nmap scanning, but the MARS doesn't show me any incidents.
I added the Linux host under Admin->Security and Monitor Devices -> Add -> Device Type: Add SW security apps on new host. Then i configured the ip, i chose Linux as the operating system and "Rceive" at the Logging Info.
I also configured the Linux to send syslog messages to MARS:
i added in the /etc/syslog.conf file, the next line:
I sounds like you're doing everything right, it's just that Mars hasn't been configured to parse and understand those particular log entires. They will get parsed as "generic linux event". If you aren't even seeing the events in Mars, then something else is going on and we can help you with that too, just let us know.
The way to test this is to run a "real-time" query in Mars for the Linux box(query type = all matching events). See:
If WSA stopped responding to Web requests and a reboot fixed it ... may be also if Cisco TAC confirmed you are hit with the Bug CSCve59632
Cisco Bug CSCve59632 affects WSA, As when Certain number o...
This document describes how to configure a site-to-site (LAN-to-LAN) IPSec IKE Version 1 (IKEv1) tunnels using Virtual Tunnel Interface (VTI) between two Cisco ASA. ASA VPN module was enhanced with this logical interface in version 9.7(1) and...
Helps meet PCI compliance.
Threat protection built into ISR and ISRv branch routers and CSR
Complements ISR Integrated Security
Lightweight IPS solution with low TCO (Total Cost of Ownership) and automated s...