2-57
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 2 Reporting and Mitigation Devices Overview
Integrating MARS with 3
rd
-Party Applications
log { source(net); destination(loghost); };
Configure Kiwi Syslog Server to Forward Events to MARS
We recommend the following settings in the configuration options of the Kiwi Syslog Daemon to ensure
good integration of Kiwi with MARS:
Step 1
Expand the
File > Setup > Rules > Actions tree.
Step 2
Right on
Actions
and click
Add an Action
.
Step 3
Enter a name for the action, such as “Forward to pncop”.
Step 4
For the following fields, enter the following values:
•
Destination IP address or hostname
— Enter the IP address of the MARS Appliance.
•
Protocol
— UDP
•
New Facility
— No Change
•
New Level
— No Change
•
Port
— 514
•
Send with RFC 3164 header information
— Selected if the syslog server receives syslog
messages directly from the source devices only. Clear if the syslog server also receives syslog
messages from relays. Do not configure mixed relays.
This additional header is necessary for the supported device types that do
not
have
HOSTNAME in the syslog messages; thereby allowing MARS to correctly identify the original
sending device. However, this option cannot be used on a Kiwi relay of relay. To support a Kiwi
relay of relay in MARS, the first relay must have this option selected and must receive syslog
messages only from the source devices, and all other relays must have this option cleared and
must only receive syslog messages from other Kiwi relays, not directly from devices.
•
Retain the original source address of the message
— Cleared.
Step 5
If you are using SNARE agents, click
Setup > Modifiers
and clear “Replace non printable characters
with <ASCII value>”
If this value is selected, tabs appear as
<009>
in the Windows event logs, which prevents MARS from
parsing the events correctly.
Step 6
Save your changes.
Add Syslog Relay Server to MARS
In addition to representing each of the potential reporting devices, you must define the syslog relay
server so that MARS knows for which messages it should attempt to discover the true reporting device.
To add a syslog relay server, you must add it as a security software application running on a host.
To add a syslog relay server, follow these steps:
Step 1
Select
Admin > System Setup > Security and Monitor Devices >
Add
.
Step 2
Do one of the following:
•
Select
Add SW Security apps on a new host
from the Device Type
list, and continue with
Step 3