Cisco CS-MARS-20-K9 - Security MARS 20 User Manual page 488

Security mars local controller
Table of Contents

Advertisement

Retrieving Raw Messages
If you want data that does not fall within the Cached Files time range, select the Force Generate
Files check box.
If there is no cached file information, select the Force Generate Files check box.
If no cached file data is shown, then no previous queries have been performed and stored. For example,
if you preform three separate queries, using time range A, from the database sing the time range, saving
the files to the local MARS Appliance. If you later specify the same time range A and do the retrieval
again but you do not clear the Force generate files check box, the system performs the query, generating
the file again. However, if you have already retrieved and stored some data before, you can specify to
retrieve them from those saved files by clearing the Force generate files check box.
Enter the maximum number of retrieved files to retain in the Maximum No. of Files field.
Step 6
This value refers to the maximum number of event files to be generated for this query.
Requesting large numbers of files can take some time.
Note
Select the list of devices for which you want to pull event data in the Reporting Devices list.
Step 7
You can select a specific device by name or All Devices.
Click Submit.
Step 8
While MARS is generating your files, you can still use the system for other tasks.
Note
Result: The Retrieving Progress 0% screen appears. When the operation is complete, the Raw Message
Files screen appears, identifying a new Gzip archive file with a filename based on specified time range.
To download and view the generated raw message file, click Click Here to Download next to the
Step 9
filename.
The filename adheres to the following syntax:
YYYY-MM-DD-HH-MM-SS_YYYY-MM-DD-HH-MM-SS.gz.
Use WinZip or another archive expansion program to extract the contents of the Gzip archive file.
Step 10
Once the textfile is extracted from the GNU Zip archive format, its contents resemble the following:
Step 11
33750»Wed Jul 27 16:16:06 PDT 2005»BR-FW-1»10.4.1.1 Mon Jan 6 11:05:34 2003 <134>Jan 06
2003 11:03:53: %PIX-6-302001: Built inbound TCP connection 21000 for faddr 10.1.2.4/9000
gaddr 10.1.5.20/80 laddr 10.1.5.20/80
where it reads: device ID>>date>>device name>>raw message.
User Guide for Cisco Security MARS Local Controller
24-6
Chapter 24
System Maintenance
78-17020-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

Mars 20Mars 50Mars 100Mars 200

Table of Contents