cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
996
Views
0
Helpful
1
Replies

Big Trouble for the CS-MARS

Chung-Jen Kuo
Level 1
Level 1

Currently, I have some trouble in CS-MARS, and hope anyone can give me some suggestion.

Recently, we upgrade the IDS from McAfee 4.x -> 5.x.  However, it was not on the support list of the CS-MARS.

The way to solve it was to create a new custom device in the CS-MARS 6.x.  However, there are over 4000 event types need to be associated for the devices.

Therefore, does any easy way to do it?

Thanks for any recommandation.

K

1 Reply 1

Scott Fringer
Cisco Employee
Cisco Employee

K;

  There is no easy/automated method to add those 4,000 custom events to CS-MARS.  It may be possible to lower the number by creating broad matching criteria to summarize multiple different McAfee events into a single CS-MARS event.  You may also want to consider creating event parsers for only those McAfee events that are deemed most critical to your environment.

Scott

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: