20-13
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 20 Queries and Reports
Viewing Events in Real-time
Saving the Query
You can save query criteria to re-use as reports or rules.
To save a query as a report
This takes the query that you are using and creates a report. For more information on creating reports,
see
Reports, page 20-23
.
To save a query as a rule
This takes the query to the rules page, populating the rules with the selected query criteria. Likely, you
must identify additional criteria to complete the rule. For more information on creating rules, see
Rules,
page 21-1
.
Viewing Events in Real-time
The Real-time Event viewer is a query option that permits you to view real-time events as follows:
•
View raw events as they stream to MARS before they are sessionized, with a maximum 5-second
delay
•
View a sessionized event stream—more delay is possible when there are many events in a session
The real-time events display as a continuously scrolling screen. You can configure query criteria to filter
what is displayed. When viewing raw events, sessionization is not impeded, all the parsed raw events are
sessionized per normal MARS operation. MARS.
The Real-time Event viewer is available for the following query result formats that support ranking by
time (
Order/Rank
field set to
Time
):
•
Matched Incident Ranking
•
All Matching Sessions
•
All Matching Sessions, Custom Columns
•
All Matching Events
•
All Matching Event Raw Messages
•
NAT Connection Report
•
MAC Addresses Report
•
Unknown Event Report
•
Detailed NAC Report
Restrictions for Real-time Event Viewer
Real-time event queries should be made
only
from a browser instance that was used to login to MARS.
The real-time query will not have reliable results if it is executed from a browser instance spawned from
the original login instance (for example, a new browser window launched with
Ctrl+N
,
File>New>New
Window
, or
right-click
{link on MARS interface}>
Open in New Window
).
Multiple real-time queries can operate in multiple browser instances at the same time, but you
must
login
to MARS with each browser instance.