24-4
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 24 System Maintenance
Retrieving Raw Messages
Retrieve Raw Messages From Archive Server
Use this selection if archiving is enabled.
To retrieve event data from an archive server, follow these steps:
Step 1
Click
Admin
>
System Maintenance > Retrieve Raw Messages
.
Figure 24-2
Retrive Raw Messages Page (4.2.x)
Step 2
Specify the time range by specifying values in the Start and End fields.
Step 3
Verify that
Retrieve Data From Archived Files
is selected.
The data will be retrieved from the server identified under Admin > System Maintenance > Data
Archiving.
Step 4
Click
Submit
.
Note
While MARS is generating your files, you can still use the system for other tasks.
Result
: The Retrieving Progress 0% screen appears. When the operation is complete, the Raw Message
Files screen appears, identifying a new Gzip archive file with a filename based on specified time range.
Step 5
To download and view the generated raw message file, click Click Here to Download next to the
filename.
The filename adheres to the following syntax:
YYYY-MM-DD-HH-MM-SS_YYYY-MM-DD-HH-MM-SS.gz.
Step 6
Use WinZip or another archive expansion program to extract the contents of the Gzip archive file.
Step 7
Once the textfile is extracted from the GNU Zip archive format, its contents resemble the following:
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...