Welcome! This is a website that everyone can build together. It's easy!

Location: TechWiseTV

Discussion: CSMARS

Keyword tags: None

Watch
ru1ofus

ru1ofus
CSMARS
Feb 25 2008, 3:35 PM EST
Is Cisco MARS a good solution for Windows syslog aggregation? 1  out of 1 found this valuable. Do you?    
JimmyRay10acn
JimmyRay10acn
RE: CSMARS
Feb 26 2008, 6:05 PM EST
You could indeed do this with MARS, but MARS is also much more then just that piece. You can config MARS to take action on those entries as well. When I config MARS for Windows logging, I use SNARE to push the logs to CS-MARS. It works much better that way and purdy darn close to real time Do you find this valuable?    
baddogsettle

baddogsettle
RE: CSMARS
Apr 3 2008, 2:41 PM EDT
We are using SCOM (MOM 2007) which archives server security events to a SQL database. Can MARS leverage this as a feed for coorelation and reporting? Do you find this valuable?    
JimmyRay10acn
JimmyRay10acn
RE: CSMARS
Apr 3 2008, 3:25 PM EDT
There is an install method in the CS-MARS manual for config'ing CS-MARS with MS-SQL. You will still need to go thru and add the corrolation piece so that the entries are understood. Do you find this valuable?    
Top Contributors