A-2
User Guide for Cisco Security MARS Local Controller
78-17020-01
Appendix A Cisco Security MARS XML API Reference
XML Incident Notification Data File and Schema
XML Incident Notification Data File Sample Output
Example A-1
is XML incident notification data generated by the events that trigger the rule “CS-MARS
Database Partition Usage.”
Example A-1
XML Incident Notification Data File Contents
<?xml version="1.0" encoding="UTF-8"?>
<CSMARS-NOTIFICATION>
<Header>
<Version>1.0</Version>
<GenTimeStamp>May 23, 2007 8:13:19 AM PDT</GenTimeStamp>
<CSMARSHostIpAddr_eth0>10.2.3.48</CSMARSHostIpAddr_eth0>
<CSMARSHostIpAddr_eth1>192.168.1.110</CSMARSHostIpAddr_eth1>
<CSMARSHostName>pnmars</CSMARSHostName>
<CSMARSZoneName />
<CSMARSVersion>4.2.2</CSMARSVersion>
</Header>
<Data>
<Incident id="287001899">
<StartTime>May 23, 2007 8:13:09 AM PDT</StartTime>
<EndTime>May 23, 2007 8:13:10 AM PDT</EndTime>
<Severity>HIGH</Severity>
<Session id="286913412">
<Instance>0</Instance>
<SessionEndPoints>
<Source ipaddress="10.3.50.200" />
<Destination ipaddress="248.64.35.88" />
<SourcePort>15330</SourcePort>
<DestinationPort>3890</DestinationPort>
<Protocol>6</Protocol>
</SessionEndPoints>
<Event id="286914062">
<EventType id="1135" />
<TimeStamp>May 23, 2007 8:13:09 AM PDT</TimeStamp>
<ReportingDevice id="128783" />
<RawMessage>Wed May 23 08:13:09 2007 <134>%PIX-2-106001: Inbound TCP
connection denied from 10.3.50.200/15330 to 248.64.35.88/3890 flags FIN on interface
inside</RawMessage>
<FalsePositiveType>NOT_AVAILABLE</FalsePositiveType>
<EventEndPoints>
<Source ipaddress="10.3.50.200" />
Table A-2
Related XML Incident Notification Documents
Resource Description
Resource Location
Configuring XML incident notification on MARS
Chapter 22, “Sending Alerts and Incident
Notifications”
A ZIP file containing the XML incident
notification schema
http://www.cisco.com/application/x-zip-compres
sed/en/us/guest/products/ps6840/c1225/ccmigrati
on_09186a00806ba94b.zip
A hyper-linked component reference, generated
from the XML incident notification schema
http://www.cisco.com/application/x-zip-compres
sed/en/us/guest/products/ps6840/c1225/ccmigrati
on_09186a00806c27e3.zip
Sample XML incident notification data generated
by MARS
Appendix A, “”Example A-1
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...