cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1615
Views
0
Helpful
3
Replies

G2-ver7

matassimec
Level 1
Level 1

pkgName = G2-ver7

providerName = Local CS-MARS box

providerId = Local.CS-MARS.box

pkgVersion = 7.0-0410-2009

pkgType = DEVICE_SUPPORT

pkgDescription = G2 MEC CIP

creationTime = 2009-04-10T08:54:56.475

fileName = G2-SecureComputing-ver7.zip

md5checksum = 0B9824EE0DD122B9214DB52890762DC0

fileSize = 14053

marsVersion = 6.0.2(3102) 31

totalProviders = 2

totalDts = 1

totalDets = 122

totalEts = 82

totalEtgs = 0

totalRules = 0

totalRuleGrps = 0

totalReports = 0

totalReportGrps = 0

provider id: Local.CS-MARS.box

provider name: Local CS-MARS box

deviceType model: SIDEWINDER 410

deviceType vendor: Secure Computering

deviceType version: 7

det  count: 122

provider id: www.cisco.com

provider name: Cisco Systems, Inc.

et  count: 82

3 Replies 3

jloewen
Level 1
Level 1

What logging format is this parser designed for? I'm sending Sidewinder Export Format (SEF) to it and getting a lot of parser errors.

The parser is designed around SEF but it has a bunch of issues. This parser will cause MARS to crash in high EPS environments, confirmed by TAC. We ended up pulling the parser out and I am building one from scratch now, I will post it when I am done.

We were experiencing the same parser errors, many of the events are written incorrectly and unique to the posters environment.

AVOID THIS PARSER!!!

Has there been any update on this parser?  I've two 410s that I need to be able to monitor on the network and would like am hesitant to use the parser listed above as it is apparently bunk?