2-58
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 2 Reporting and Mitigation Devices Overview
Integrating MARS with 3
rd
-Party Applications
•
Select
Add SW security apps on existing host
from the Device Type
list. Select the device to which
you want to add the software application and click Add. Continue with
Step 6
.
Step 3
Specify values for the following fields:
•
Device Name
— Enter the hostname of the syslog relay server. MARS maps this name to the
reporting IP address. This name is used in topology maps, queries, and as the primary management
station in the Security and Monitoring Device list.
•
Reporting IP
— Enter the IP address of the interface in the syslog relay server from which MARS
will receive syslog messages.
This address represents the physical IP address of the syslog relay server. To learn more about the
reporting IP address, its role, and dependencies, see
Understanding Access IP, Reporting IP, and
Interface Settings, page 2-8
.
Step 4
Under Enter interface information, enter the interface name, IP address, and netmask value of the
interface in the syslog relay server from which syslog messages will be received.
This address represents the physical IP address of the syslog relay server. To learn more about the
interface settings, its role, and dependencies, see
Understanding Access IP, Reporting IP, and Interface
Settings, page 2-8
.
Step 5
Click
Apply
to save these settings.
Step 6
Click
Next
to access the Reporting Applications tab.
Step 7
Select
Generic Syslog Relay ANY
from the Select Application list, and click
Add
.
Step 8
Click
Submit
to add this application to the host.
Result
: Generic Syslog Relay ANY appears in the Device Type list.
Step 9
Click the
Vulnerability Assessment Info
link to define the host information that MARS uses to
determine false positive attacks against this host. Continue with
Define Vulnerability Assessment
Information, page 10-12
.
Step 10
Click
Done
to save the changes.
Result
: The host appears in the Security and Monitoring Information list.
Step 11
To activate the device, click
Activate
.
Add Devices Monitored by Syslog Relay Server
While you do not have to configure each reporting device to forward syslog messages to the MARS
Appliance, you must define the device to MARS so that when it parses the syslog messages forwarded
by the relay server, then it is able to match the true reporting IP address to that of a known reporting
device type. By knowing the reporting device type, MARS can correctly parse the events.
The process for adding these reporting devices is the same as if there were no syslog relay server except
that you do not configure the reporting device to forward events to the MARS Appliance. In the MARS
web interface, you should still configure the reporting devices so that MARS can discover their settings
and to perform any mitigation operations.