cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
668
Views
0
Helpful
3
Replies

Retrieve old raw data and syslog

shairolbit
Level 1
Level 1

If we did not backup all of the syslog that stored in CSMARS database, how can we retrieve it back from the security devices/appliances/servers and then send it back to CSMARS, or can CSMARS pull the old/backdated syslog from the devices again?

3 Replies 3

Scott Fringer
Cisco Employee
Cisco Employee

There is no method to pull the old events from a monitored security device back to CS-MARS.  To protect against data loss on the CS-MARS you should work to enable data archiving.

Scott

We experienced with 1  incident where the disk corrupted and the appliance have to be replaced.  We did not backup all the data but only managed to setup daily archived,  the problem occurred when we wanted to retrieved the old syslogs data  from the security devices/appliances that integrated with CSMARS. Is  there any method that we can used to retrieve back the previous syslogs  that have not been stored in CSMARS database, and send it again to  CSMARS from the devices/appliances?

There is no supported method to retrieve past events from a security device into CS-MARS.  Events are forwarded real-time to the CS-MARS.  CS-MARS only allows restoring event data from its own data archives.

Scott