<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Creating a query or report in MARS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/creating-a-query-or-report-in-mars/m-p/697507#M92329</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, I needed a sanity check.&lt;/P&gt;&lt;P&gt;I was able to do a query that I believe gave me the "top source" ip's for my site but the duration was not doable.&lt;/P&gt;&lt;P&gt;-Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 22 Sep 2006 19:21:55 GMT</pubDate>
    <dc:creator>dfreemire</dc:creator>
    <dc:date>2006-09-22T19:21:55Z</dc:date>
    <item>
      <title>Creating a query or report in MARS</title>
      <link>https://community.cisco.com/t5/network-security/creating-a-query-or-report-in-mars/m-p/697505#M92324</link>
      <description>&lt;P&gt;I need to create reports for two things:&lt;/P&gt;&lt;P&gt;How many users (IPs) hit our website more than once per day,&lt;/P&gt;&lt;P&gt;and How many users browse our site for more than 20 minutes at a time.&lt;/P&gt;&lt;P&gt;Since these "events" are normal and not breaking any "rules" can I query or report on them?&lt;/P&gt;&lt;P&gt;I have an FWSM and an IDSM2 behind that (inside) logging to the MARS.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:14:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/creating-a-query-or-report-in-mars/m-p/697505#M92324</guid>
      <dc:creator>dfreemire</dc:creator>
      <dc:date>2019-03-10T10:14:09Z</dc:date>
    </item>
    <item>
      <title>Re: Creating a query or report in MARS</title>
      <link>https://community.cisco.com/t5/network-security/creating-a-query-or-report-in-mars/m-p/697506#M92326</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Because of the way the HTTP protocol works,&lt;/P&gt;&lt;P&gt;what you're asking for would be very difficult  [if not impossible] to do reliably based soley on events coming info CSMARS from FWSM and IDSM2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you really want to do this, your best bet is to use a tool to analyze the actual web server logs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Sep 2006 17:34:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/creating-a-query-or-report-in-mars/m-p/697506#M92326</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2006-09-22T17:34:05Z</dc:date>
    </item>
    <item>
      <title>Re: Creating a query or report in MARS</title>
      <link>https://community.cisco.com/t5/network-security/creating-a-query-or-report-in-mars/m-p/697507#M92329</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, I needed a sanity check.&lt;/P&gt;&lt;P&gt;I was able to do a query that I believe gave me the "top source" ip's for my site but the duration was not doable.&lt;/P&gt;&lt;P&gt;-Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Sep 2006 19:21:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/creating-a-query-or-report-in-mars/m-p/697507#M92329</guid>
      <dc:creator>dfreemire</dc:creator>
      <dc:date>2006-09-22T19:21:55Z</dc:date>
    </item>
  </channel>
</rss>

