15-4
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 15 Configuring Custom Devices
Adding User Defined Log Parser Templates
Note
If a log template attempts to parse the header information, the custom parser will fail and indicate that
the message is an Unknown Device Event Type. The parser only receives the payload information.
Step 1
Go to the
Admin > Custom Setup
tab.
Step 2
Click the
User Defined Log Parser Templates
.
Step 3
Select the newly created/existing Device or Application
from the Device/Application Type list.
Step 4
To add a log template, click
Add
located in the Log Templates for area.
A log template ties directly to the particular message that you want to parse. A log template is composed
of one or more Event Types that describe the contents of the message. Using the Event Types, MARS
parses the message when it is received.
Step 5
Enter a value in the
Log ID
field. This value is a unique string value that identifies the log message.
The Log ID field provides an opportunity to map this message number or another moniker used by the
device to the custom event type that you are developing. You can use this value to clarify the device
messages for which you have developed custom event types.
Step 6
Enter
Description
- a description of the log message.
Step 7
Map the log to an Event Type.
Note
The MARS Appliance comes with a number of predefined Event Types. To display them, select
System
(for example) from the list above the Event Type select window and click
Get
)
Step 8
New
Event Types
can be added by clicking
Add
below the Event Type list.
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...