04-10-2009 09:46 AM
pkgName = G2-ver7
providerName = Local CS-MARS box
providerId = Local.CS-MARS.box
pkgVersion = 7.0-0410-2009
pkgType = DEVICE_SUPPORT
pkgDescription = G2 MEC CIP
creationTime = 2009-04-10T08:54:56.475
fileName = G2-SecureComputing-ver7.zip
md5checksum = 0B9824EE0DD122B9214DB52890762DC0
fileSize = 14053
marsVersion = 6.0.2(3102) 31
totalProviders = 2
totalDts = 1
totalDets = 122
totalEts = 82
totalEtgs = 0
totalRules = 0
totalRuleGrps = 0
totalReports = 0
totalReportGrps = 0
provider id: Local.CS-MARS.box
provider name: Local CS-MARS box
deviceType model: SIDEWINDER 410
deviceType vendor: Secure Computering
deviceType version: 7
det count: 122
provider id: www.cisco.com
provider name: Cisco Systems, Inc.
et count: 82
09-16-2009 04:56 AM
What logging format is this parser designed for? I'm sending Sidewinder Export Format (SEF) to it and getting a lot of parser errors.
09-24-2009 03:19 PM
The parser is designed around SEF but it has a bunch of issues. This parser will cause MARS to crash in high EPS environments, confirmed by TAC. We ended up pulling the parser out and I am building one from scratch now, I will post it when I am done.
We were experiencing the same parser errors, many of the events are written incorrectly and unique to the posters environment.
AVOID THIS PARSER!!!
12-08-2009 11:06 AM
Has there been any update on this parser? I've two 410s that I need to be able to monitor on the network and would like am hesitant to use the parser listed above as it is apparently bunk?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide