cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
508
Views
5
Helpful
2
Replies

Black ICE logging into MARS

ab_parkhi
Level 1
Level 1

Hi,

We have Host based IPS Balck ICE and we are tring to log alerts into MARS.

Is there any way to do this.

Thanks in advance

Aniruddha

2 Replies 2

ksimsimon
Level 1
Level 1

Hello Aniruddha,

the best way is to search on ISS side:

http://iss.custhelp.com/cgi-bin/iss.cfg/php/enduser/std_alp.php

or open there a question.

ISS is now supported from Siemens and Black ICE will be end of support next year

regards

Klaus

mhellman
Level 7
Level 7

AFAICT, it isn't supported directly. MARS does support ISS RealSecure 6.5 and 7.0, but those products are in a different solution space...so the events they emit are likely to be different. You can create custom parsers for MARS, you'll have to figure out whether:

1) BlackICE can send events to MARS via syslog or SNMP

2) whether you can get the format of the messages and a complete list of them