cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1056
Views
0
Helpful
1
Replies

Big Trouble for the CS-MARS

Chung-Jen Kuo
Level 1
Level 1

Currently, I have some trouble in CS-MARS, and hope anyone can give me some suggestion.

Recently, we upgrade the IDS from McAfee 4.x -> 5.x.  However, it was not on the support list of the CS-MARS.

The way to solve it was to create a new custom device in the CS-MARS 6.x.  However, there are over 4000 event types need to be associated for the devices.

Therefore, does any easy way to do it?

Thanks for any recommandation.

K

1 Reply 1

Scott Fringer
Cisco Employee
Cisco Employee

K;

  There is no easy/automated method to add those 4,000 custom events to CS-MARS.  It may be possible to lower the number by creating broad matching criteria to summarize multiple different McAfee events into a single CS-MARS event.  You may also want to consider creating event parsers for only those McAfee events that are deemed most critical to your environment.

Scott