2-17
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 2 Reporting and Mitigation Devices Overview
Adding Reporting and Mitigation Devices
From the Security and Monitor Devices page, you can add or edit the reporting devices and mitigation
devices that MARS monitors. To access this page, click
Admin > System Setup > Security and
Monitor Devices
. You can search for, add, edit, delete, change display status, and load devices from the
seed file.
The device support is categorized into three categories:
•
HW-Based Security Devices.
Hardware-based devices represent routers, switches, and other
dedicated security appliances. You can add such reporting devices by selecting the appropriate
device.
•
SW-Based Security Devices.
Software-based devices represent applications that reside on a host,
rather than a dedicated appliance. You can add reporting device on a new host by selecting
Add SW
security apps on new host
or on an existing host by selecting
Add SW security apps on existing
host
.
•
On-Demand Security Services.
Security services represent subscription-based services provided
by vendors using a central security operations center (SOC) with remote monitoring nodes. These
services, such as Qualys QualysGuard, represent systems from which MARS periodically pulls data.
You can add such reporting devices by selecting the appropriate service. These devices also require
you to define a schedule for pulling data (see
Scheduling Topology Updates, page 2-39
).
The complete list of supported devices is presented in the
Supported Devices and Software Versions for
Cisco Security MARS Local Controller 4.2.x and 5.2.x
document. Devices are added to this list on an
ongoing basis via software upgrade packages. See
Install and Setup Guide for Cisco Security
Monitoring, Analysis, and Response System
for details on how to upgrade your MARS Appliance.
MARS can also support any syslog or SNMP devices, even if they do not appear on the list of devices
supported by the MARS. You can enter any syslog or SNMP device into the network topology, configure
it to report data to the MARS, and query it using a free-form query. (See
To Run a Free-form Query,
page 20-2
.)
For more information on adding devices, see:
•
Add Reporting and Mitigation Devices Individually, page 2-17
•
Add Multiple Reporting and Mitigation Devices Using a Seed File, page 2-20
•
Adding Reporting and Mitigation Devices Using Automatic Topology Discovery, page 2-25
Regardless of the method that you have used to add the devices, you should also perform the following
tasks:
•
Verify Connectivity with the Reporting and Mitigation Devices, page 2-26
•
Activate the Reporting and Mitigation Devices, page 2-27
Add Reporting and Mitigation Devices Individually
In general, you have two choices for adding devices that you want to monitor into your MARS. You can
create a seed file or you can add each device manually. Seed file support is limited to a few device types,
see
Column E, page 2-23
for the devices supported.
When manually configuring devices, select the devices that are most interesting to you. Once added, you
can come back and edit them as necessary. Manual configuration is also useful when you add or change
a single security device on your network.
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...