cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
462
Views
0
Helpful
3
Replies

MARS and SNORT

adenter
Level 1
Level 1

Has anyone tackled error messages when recieving events from Snort 2.3.3? MARS says Unknown Device Event Type for everything so far. Drill down on the raw shows semi important things like an nmap probe or a port scan but MARS template doesnt seem to recognize.

3 Replies 3

dmitry
Level 1
Level 1

my guess that MARS expects the Snort syslog messages with a certain facility - LOCAL4 to start parsing / matching the Snort events to the local signatures:

output alert_syslog: LOG_LOCAL4 LOG_ALERT

bcarroll
Level 1
Level 1

My guess is its a support issue. Are you running MARS 4.1.4? According to the release notes at http://www.cisco.com/en/US/products/ps6241/prod_release_note09186a0080607e86.html#wp1124250 it says that version of snort is a new vendor.

adenter
Level 1
Level 1

I rcvd a note from a Protego/Cisco person who explained that SNORT support is for generator with ID of 1 only. The generator that I was seeing was Portscan with an ID of 122.