Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hello,I am having a problem. I get a MARS-25 from one service provider, which didn't provide pnadmin password neither Software License Claim Sertificate. I would re-image the applience, but this would lead to re-entering the license information on in...
Hello,At the moment I am prepairing the documentation for MARS-25 implementation. I have to consider the total amount of compressed data which will be stored in arcive data base. The plan is to have EPS around 300 (mainly syslog messages). I was look...
Hi,Does anybody know what are the capabilities of MARS to support Imperva FireWalls? Maybe someone has this type of FW in their MARS environment? I am concerning about pulling as much info as possible to CS-MARS from this device. I would appreciate i...
Hello,I am concerning about the way to use only one MARS applience for archived logs re-activation and investigation on the same machine. Is it possible or the second applience is the only option? Why MARS can not operate with archived events on a si...
Hello,Could somone please tell me how much of the storage is required for archiving the day worth MARS-25 data excluding all the storage space required for event information (assuming that there are no reporting devices connected)?Another question is...
learnsec 0,Truncated refers to a raw message being made smaller. For exaple, if your IPS somehow generates a raw message as large as 1.7 MB the MARS applience would store only 1.5 MB of the message payload. That's how I understand it. Refering to cis...
learnsec 0,The 1.5 MB is the limitation of single raw message size. Refer to User Guide (http://www.cisco.com/en/US/partner/docs/security/security_management/cs-mars/6.1/device/configuration/guide/GbkDcnfgd.html) section About Raw Message Size Limita...
Thank you Sunil,Sorry, I still can't get it. Is the additional space for recovery and config files, session and incident data included in those figures? Because here is what I get:10 EPS x [seconds per year] x 200 B/event x 0.1 (compression 10:1)= 63...