I have some difficulty getting CS-MARS to recognise SNMP trap sent by ISS Proventia G400 to MARS.
The MARS 4.2.x user guide mentioned RealSecure 7.0, but I tried to configured a G400 device as a reporting device with "device type" set to RealSecure 7.0, and generated a few SNMP trap from the G400 IPS to MARS. But when I tried use the query page to retrieve the events, no events were returned.
Anybosy know if I can set G400 as "RealSecure 7.0" device ??
Or do I need to use the User Defined Log Parser Templates for ISS G400 ?
Anyone have an example to define a template for SNMP trap ? The user guide only give us the example for syslog mdg, not SNMP trap.