24-6
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 24 System Maintenance
Retrieving Raw Messages
•
If you want data that does not fall within the Cached Files time range, select the
Force Generate
Files
check box.
•
If there is no cached file information, select the
Force Generate Files
check box.
If no cached file data is shown, then no previous queries have been performed and stored. For example,
if you preform three separate queries, using time range
A
, from the database sing the time range, saving
the files to the local MARS Appliance. If you later specify the same time range
A
and do the retrieval
again but you do not clear the Force generate files check box, the system performs the query, generating
the file again. However, if you have already retrieved and stored some data before, you can specify to
retrieve them from those saved files by clearing the Force generate files check box.
Step 6
Enter the maximum number of retrieved files to retain in the Maximum No. of Files field.
This value refers to the maximum number of event files to be generated for this query.
Note
Requesting large numbers of files can take some time.
Step 7
Select the list of devices for which you want to pull event data in the Reporting Devices list.
You can select a specific device by name or All Devices.
Step 8
Click
Submit
.
Note
While MARS is generating your files, you can still use the system for other tasks.
Result
: The Retrieving Progress 0% screen appears. When the operation is complete, the Raw Message
Files screen appears, identifying a new Gzip archive file with a filename based on specified time range.
Step 9
To download and view the generated raw message file, click Click Here to Download next to the
filename.
The filename adheres to the following syntax:
YYYY-MM-DD-HH-MM-SS_YYYY-MM-DD-HH-MM-SS.gz.
Step 10
Use WinZip or another archive expansion program to extract the contents of the Gzip archive file.
Step 11
Once the textfile is extracted from the GNU Zip archive format, its contents resemble the following:
33750»Wed Jul 27 16:16:06 PDT 2005»BR-FW-1»10.4.1.1 Mon Jan 6 11:05:34 2003 <134>Jan 06
2003 11:03:53: %PIX-6-302001: Built inbound TCP connection 21000 for faddr 10.1.2.4/9000
gaddr 10.1.5.20/80 laddr 10.1.5.20/80
where it reads:
device ID
>>
date
>>
device name
>>
raw message
.
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...