15-3
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 15 Configuring Custom Devices
Adding User Defined Log Parser Templates
Figure 15-2
Device Type Definition
Step 4
Choose the Type - Appliance or Software.
•
Appliance - A hardware device that can send logs to the MARS Appliance
•
Software - An application running on a host and the host can be configured to send logs to the
MARS Appliance
Step 5
Enter the Vendor, Model and Version for the Device or Application. (For Example, Cisco PIX 7.0)
Step 6
Click
Submit
.
Figure 15-3
User Defined Device/Application Type
Add Parser Log Templates for the Custom Device/Application
While the raw message for an event does include the header information, MARS removes the header
prior to sending the payload to the custom parser. When writing a parser log template, do not include the
header fields.