cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2165
Views
0
Helpful
4
Replies

Integration of IronPort into CS-MARS

lekchandmantri
Level 1
Level 1

Can anyone advice how to integrate IronPort into CS-MARS. Thanks.

4 Replies 4

Jennifer Halim
Cisco Employee
Cisco Employee

Ironport is not a supported MARS device.

Here is the list of all devices supported by MARS for your reference:

http://www.cisco.com/en/US/docs/security/security_management/cs-mars/6.0/compatibility/local_controller/dtlc60x.html

Hi halijenn,

Thanks for your prompt response.

I agree, but we can add IronPort as custom device and write custom log parsers for that. I am confused which logs do we need to capture and write parsers as IronPort does not provide message log in one line I mean it break in pieces and maintain MID for each line.

Secondly, I have setup custom device, I received messages but I got "Buffer overflow" error message in IronPort and stop sending logs to CS-MARS.

Can you please advice so as to what could be the cause for this.

I really appreciate if you could advice some interesting things which we can log into CS-MARS from IronPort. Thanks.

What logs are IronPort device sending? syslog messages or snmp traps? Generally MARS pretty much just takes syslog and/or snmp. Other types of logging is normally pretty difficult to parse in MARS, and requires complex custom parser to be written.

I have setup to receive syslog messages from ironport. We configured IronPort to push syslog maillog messages to CS-MARS. It received for a while and it stopped giving error in Ironport something like CSMARS buffer overflow. Below are some messages received from IronPort in CS-MARS.

Parsing error or event type unknown: <22>May 14 12:47:35 MailLog_CSMARS: Info: Message done DCID 61561334 MID 102046326 to RID [1, 2, 3, 4]

Parsing error or event type unknown: <22>May 14 12:47:36 MailLog_CSMARS: Info: MID 102046330 interim AV verdict using Sophos CLEAN

Can you check if anyone has implemented? Thanks.