10-4
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 10 Configuring Generic, Solaris, Linux, and Windows Application Hosts
Microsoft Windows Hosts
Figure 10-2
Identifying a Solaris or Linux Device From Which to Receive Logs
Step 3
Enter values for the following fields:
•
Device Name.
Enter the hostname for this device.
•
Reporting IP
. Enter the IP address from which the logs will be pulled.
Step 4
In the Operating System list, select either
Solaris
or
Linux
to match the operating system running on
the host.
Step 5
Select
Logging Info
and select
Receive
, then click
Submit.
Step 6
Click
Apply
to add the device.
Microsoft Windows Hosts
MARS processes data pulled from hosts running Microsoft Windows. This data includes the events
found in the security event log as well application event and system event logs. You can use one of two
methods to retrieve the logs from a host running Microsoft Windows, whether it is a server or
workstation version:
•
You can configure MARS to pull the logs from the host.
•
You can configure the host to send the log data to the MARS Appliance.
These two methods are mutually exclusive; in other words, you cannot configure both methods. Your
decision in which method to use depends on how much time you can spend preparing the host, the
desired load on the MARS Appliance, and how near real-time you want MARS to process the event data.
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...