1-15
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 1 STM Task Flow Overview
Checklist for Monitoring Phase
6.
Monitor system and network health.
The STM system is more than your MARS Appliance; it includes all reporting devices and mitigation devices
and any MARS Appliances. When assessing the health of the system, you should monitor the health of each of
these devices. You can monitor your system health by using inspection rules that generate notifications for
anomalous behavior, by generating system health queries and reports, and by manually reviewing the system logs
of MARS.
MARS provides reports about use of common resources, including CPU, bandwidth, and memory. To simplify
the monitoring of system health, you can define a report group that organizes these reports into a meaningful
collection. You can also restrict the presentation of those reports and queries to specific user roles.
Because reports can be scheduled, you can notify the appropriate users each time the report is updated.
Tip
If you cannot view the resource usage of a reporting device, verify that you have enabled the Monitor
Resource Usage option as part of that device definition in Admin > System Configuration > Security and
Monitored Devices. For the list of devices that can be configured to provide this data, see
Configuring
Resource Usage Data, page 2-41
.
MARS also includes detailed logs about the status of the appliance itself, as well as several command-line
utilities that present status on the health of the appliance.
Result
: The users responsible for monitoring the system and network health understand the tools and reports
provided by MARS to perform these functions.
For more information, see:
•
Rule and Report Groups, page 21-24
•
Rule and Report Group Overview, page 21-25
•
Configuring Resource Usage Data, page 2-41
•
pnstatus, page A-39
•
pnlog, page A-30
•
Setting Runtime Logging Levels, page 24-1
•
Viewing the MARS Backend Log Files, page 24-2
•
Viewing the Audit Trail, page 24-3
•
Retrieving Raw Messages, page 24-3
Task