redray8
Level 1
Level 1
Member since ‎01-15-2004
‎08-18-2017

User Statistics

  • 37 Posts
  • 0 Solutions
  • 20 Helpful votes Given
  • 0 Helpful votes Received
Recent Badges
First Discussion
5 Discussion Posts
30 Discussion Posts
20 Discussion Posts
10 Discussion Posts
1 Reply
10 Replies
5 Replies

User Activity

I am running 6.0.3 MARS, Data Package Version: 32, Signature Version: 396. We have recently stood up a Enterasys Dragon 7.2.3. I followed the instructions for adding the device type for a Dragon 6.x device and with some differences on the Enterasys ...
Is there any way to export raw logs from CS-MARS or is the Query option (or the syslog relay) the only way to interrogate against any log data that is collected by CS-MARS?So for instance, I wanted to dump either all (or part based on date/time range...
Is there any way to perform a NOT on a regular expression match. For instance, in PCRE it would be !"/[A-Z]+/i". I cannot determine if there is a valid way to do this on a Cisco IDS regex string. Any help or info would be greatly appreciated.
What is the best way to identify that a specific signature has fired on IDS/IPS 6.x that is feeding into a CS-MARS appliance?Would the easiest way to match "ANY" for Event Type and then do a keyword match? If so, what is it matching on, the signatur...
I have done a previous search and realize that there is no good way to convert Snort signatures to Cisco IDS/IPS custom signatures. I was wondering if anyone has ever converted the Snort "state-based" TCP string matched signature into something that...
Community Statistics
Member Since ‎01-15-2004 03:19 PM
Date Last Visited ‎08-18-2017 03:51 AM
Posts 37