4-7
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 4 Configuring Firewall Devices
Cisco Firewall Devices (PIX, ASA, and FWSM)
http://www.cisco.com/en/US/products/hw/switches/ps708/products_system_message_guide_book
09186a00804d7356.html
List of Cisco Firewall Message Events Processed by MARS
The following list of events are processed by MARS. By changing the severity level for these events to
ensure they are within the logging level you have selected, you can typically reduce the load on your
firewall logging by 5-15%. However, the primary consumer of resources will remain the session detail
events, which are processed and analyzed by MARS.
Starting with MARS version, the system can correctly parse syslogs at customized logging levels.
Therefore, you can move the syslogs processed by MARS to a lower level and then set the log to that
level, for example
logging level 6
. Use the command
logging message
message-id
level
level
on the
ASA, or PIX, to move a syslog message to a new level.
The following syslog message IDs are those required for proper sessionization. If you change the
logging level of the firewall, ensure that the following messages IDs are generated at the new level so
the MARS Appliance receives them.
Note
The syslog message IDs listed below are required for sessionization. However, other logs at the debug
or informational levels may exist that you may require for other purposes. for example, a specific URL
accessed by one user if you are doing URL filtering on the security appliance. Refer to the
Logging
Message Command, page 4-6
for pointers to the full message list for each firewall device type.
•
logging message 106100
•
logging message 106001
•
logging message 106002
•
logging message 106006
•
logging message 106007
•
logging message 106010
•
logging message 106012
•
logging message 106013
•
logging message 106014
•
logging message 106015
•
logging message 106016
•
logging message 106017
•
logging message 106018
•
logging message 106019
•
logging message 106020
•
logging message 106021
•
logging message 106022
•
logging message 106023
•
logging message 302001
•
logging message 302003
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...