15-7
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 15 Configuring Custom Devices
Adding User Defined Log Parser Templates
Figure 15-7
Define Pattern for a Log
Step 16
In the above example, the
Position
refers to the position of each KEY-VALUE sub-pattern pair. These
KEY-VALUE sub-pattern pairs are concatenated in the order of their positions and used for matching
against the raw message in an event. It does allow arbitrary whitespace between KEY and VALUE
patterns, as well as between KEY-VALUE sub-patterns.
Step 17
In the above example, the
Key-Pattern
is “
Teardown
” is a simple regular expression that does not have
any wildcards or repetitions.
Step 18
The
Parsed Field
is one of fields of a MARS event that has been fully parsed. In the above case, it is the
protocol field.
Step 19
The
Value Type
gives indication to the parser on what kind of value to expect so that suitable parsing
action can be applied on the matching sub-pattern string. By “
Choosing Protocol (String)”
as the value
type above, we indicate that the protocol field is coming in the form of a string as defined in the file
/etc/protocols in a UNIX system. For example, “
TCP
” is the string that will be captured by the value
pattern. The
Value Type
will indicate that TCP is to be converted into its protocol number, 6.
Step 20
Pattern Name
is a mnemonic given to standard regular expression patterns available for the user who is
specifying the log format. There are several common pre defined patterns with appropriate names. In the
edit box right below the
Pattern Name
list, a user can add new value names to identify value patterns
that may be commonly used in their logs. In the above figure, the value pattern captures all
word-character strings that may also include the characters ‘-‘, ‘/’ and ‘+’.
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...