10-6
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 10 Configuring Generic, Solaris, Linux, and Windows Application Hosts
Microsoft Windows Hosts
Step 9
SNARE is installed and started on the local host. A dialog box appears, prompting you to specify
whether to allow SNARE to control the EventLog configuration for the Microsoft Windows host.
Step 10
Select
Yes
to enable SNARE to control the EventLog configuration for this Microsoft Windows host.
The SNARE - Remote Event Logging for Windows user interface appears.
Step 11
To configure the Snare agent, continue with
Enable SNARE on the Microsoft Windows Host, page 10-6
.
Enable SNARE on the Microsoft Windows Host
Once you have downloaded and installed the SNARE agent on the target Microsoft Windows host, you
must configure the agent to forward the correct event data in the correct format to the MARS Appliance.
To configure the SNARE agent, follow these steps:
Step 1
Click
All Programs > InterSect Alliance > Snare for Windows
to run the SNARE - Remote Event
Logging for Windows user interface.
Step 2
Click
Setup >
Network Configuration...
.
The Network Configuration page appears.
Step 3
Specify values for the following fields:
•
Override detected DNS Name with.
Specify the IP address or DNS name of the local host in the
field.
•
Destination Snare Server address.
Specify the IP address or the DNS name of the MARS
Appliance.
Step 4
Verify that the following options are selected:
•
Allow SNARE to automatically set audit configuration
•
Allow SNARE to automatically set file audit configuration
•
Enable SYSLOG Header
Note
Verify the syslog port is 514.
Step 5
Click
Apply the Latest Audit Configuration
on the Network Configuration page.
Step 6
Click
File > Close
to close SNARE - Remote Event Logging for Windows user interface.
The SNARE agent is stopped and restarted to pick up the configuration changes.
Pull Method: Configure the Microsoft Windows Host
As an alternative to the push method, you can configure MARS to pull event log data (security,
application, and system event logs) from Microsoft Windows hosts. The pull method requires the
following steps:
1.
Ensure that the Windows host and MARS Appliance clocks are synchronized. It is recommend that
you configure a NTP server for this purpose. For more information, see
Specify the Time Settings,
page 5-10
.
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...