I have a MARS 50, and i tried to add a Linux to send syslog messages to it. I added it, i can see the linux int the topology window.
I run a nmap scan on the linux, i get a lot of syslog messages on the linux console because of the nmap scanning, but the MARS doesn't show me any incidents.
I added the Linux host under Admin->Security and Monitor Devices -> Add -> Device Type: Add SW security apps on new host. Then i configured the ip, i chose Linux as the operating system and "Rceive" at the Logging Info.
I also configured the Linux to send syslog messages to MARS:
i added in the /etc/syslog.conf file, the next line:
I sounds like you're doing everything right, it's just that Mars hasn't been configured to parse and understand those particular log entires. They will get parsed as "generic linux event". If you aren't even seeing the events in Mars, then something else is going on and we can help you with that too, just let us know.
The way to test this is to run a "real-time" query in Mars for the Linux box(query type = all matching events). See:
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...