10-11
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 10 Configuring Generic, Solaris, Linux, and Windows Application Hosts
Microsoft Windows Hosts
Step 10
Click
Submit
.
Figure 10-4
Windows Logging
Step 11
Click
Submit
to save your changes.
Step 12
Add Interface IP Address and Network Mask.
Step 13
Click
Apply.
Step 14
Click the
Vulnerability Assessment Info
link to define the host information that MARS uses to
determine false positive attacks against this host. Continue with
Define Vulnerability Assessment
Information, page 10-12
.
Step 15
Click
Done
to save the changes.
Step 16
To activate the device, click
Activate
.
If you selected the pull check box in
Step 8
, verfiy that a value has been specified for the interval at
which which MARS pulls an event log from the host. For more information, see
Windows Event Log
Pulling Time Interval, page 10-11
.
Windows Event Log Pulling Time Interval
You can now set the interval at which MARS pulls an event log from all Microsoft Windows host that
are defined as reporting devices. This feature determines how often MARS requests logs from the
Windows hosts that are configured a reporting devices.
Note
If you are using SNARE to push the log data to MARS, then you do not need to enable this setting.
To configure the Windows event log pulling time interval, follow these steps:
Step 1
Click
Admin
>
System Parameters > Windows Event Log Pulling Time Interval
.
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...