cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2159
Views
0
Helpful
4
Replies

Integration of IronPort into CS-MARS

lekchandmantri
Level 1
Level 1

Can anyone advice how to integrate IronPort into CS-MARS. Thanks.

4 Replies 4

Jennifer Halim
Cisco Employee
Cisco Employee

Ironport is not a supported MARS device.

Here is the list of all devices supported by MARS for your reference:

http://www.cisco.com/en/US/docs/security/security_management/cs-mars/6.0/compatibility/local_controller/dtlc60x.html

Hi halijenn,

Thanks for your prompt response.

I agree, but we can add IronPort as custom device and write custom log parsers for that. I am confused which logs do we need to capture and write parsers as IronPort does not provide message log in one line I mean it break in pieces and maintain MID for each line.

Secondly, I have setup custom device, I received messages but I got "Buffer overflow" error message in IronPort and stop sending logs to CS-MARS.

Can you please advice so as to what could be the cause for this.

I really appreciate if you could advice some interesting things which we can log into CS-MARS from IronPort. Thanks.

What logs are IronPort device sending? syslog messages or snmp traps? Generally MARS pretty much just takes syslog and/or snmp. Other types of logging is normally pretty difficult to parse in MARS, and requires complex custom parser to be written.

I have setup to receive syslog messages from ironport. We configured IronPort to push syslog maillog messages to CS-MARS. It received for a while and it stopped giving error in Ironport something like CSMARS buffer overflow. Below are some messages received from IronPort in CS-MARS.

Parsing error or event type unknown: <22>May 14 12:47:35 MailLog_CSMARS: Info: Message done DCID 61561334 MID 102046326 to RID [1, 2, 3, 4]

Parsing error or event type unknown: <22>May 14 12:47:36 MailLog_CSMARS: Info: MID 102046330 interim AV verdict using Sophos CLEAN

Can you check if anyone has implemented? Thanks.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: