<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-34995790.post115919435914739160..comments</id><updated>2008-04-03T14:57:01.980Z</updated><title type='text'>Comments on The Unofficial Cisco MARS Blog: Cisco MARS Starts Here!</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://ciscomars.blogspot.com/feeds/115919435914739160/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/115919435914739160/comments/default'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2006/09/cisco-mars-starts-here.html'/><author><name>Chris Durkin</name><uri>http://www.blogger.com/profile/08997829845892677696</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>3</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-34995790.post-1560386303960247909</id><published>2008-04-03T14:55:00.000Z</published><updated>2008-04-03T14:55:00.000Z</updated><title type='text'>You can drop these events and store them to the DB...</title><summary type='text'>You can drop these events and store them to the DB. I would not recommend dropping them completly, the may be usefull in the event there is a breach.</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/115919435914739160/comments/default/1560386303960247909'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/115919435914739160/comments/default/1560386303960247909'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2006/09/cisco-mars-starts-here.html?showComment=1207234500000#c1560386303960247909' title=''/><author><name>Schwag</name><uri>http://www.blogger.com/profile/06516374892105285907</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://ciscomars.blogspot.com/2006/09/cisco-mars-starts-here.html' ref='tag:blogger.com,1999:blog-34995790.post-115919435914739160' source='http://www.blogger.com/feeds/34995790/posts/default/115919435914739160' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-6387815400162831544</id><published>2007-09-27T04:42:00.000Z</published><updated>2007-09-27T04:42:00.000Z</updated><title type='text'>I get hundreds of thousands of scans, hack attempt...</title><summary type='text'>I get hundreds of thousands of scans, hack attempts, etc on my perimeter per day.  MARS sees it all and stores this as incidents, events, etc.  Should I be tuning MARS to drop these events since the vast majority show they are being blocked by the firewalls? Or should I just let MARS store them all.  Any thoughts?</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/115919435914739160/comments/default/6387815400162831544'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/115919435914739160/comments/default/6387815400162831544'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2006/09/cisco-mars-starts-here.html?showComment=1190868120000#c6387815400162831544' title=''/><author><name>teckmerc</name><uri>http://www.blogger.com/profile/01268119433342300322</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://ciscomars.blogspot.com/2006/09/cisco-mars-starts-here.html' ref='tag:blogger.com,1999:blog-34995790.post-115919435914739160' source='http://www.blogger.com/feeds/34995790/posts/default/115919435914739160' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-34995790.post-115930346389409572</id><published>2006-09-26T20:44:00.000Z</published><updated>2006-09-26T20:44:00.000Z</updated><title type='text'>Good work, keep it up please. Alec Nouvor</title><summary type='text'>Good work, keep it up please. Alec Nouvor</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/115919435914739160/comments/default/115930346389409572'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34995790/115919435914739160/comments/default/115930346389409572'/><link rel='alternate' type='text/html' href='http://ciscomars.blogspot.com/2006/09/cisco-mars-starts-here.html?showComment=1159303440000#c115930346389409572' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://ciscomars.blogspot.com/2006/09/cisco-mars-starts-here.html' ref='tag:blogger.com,1999:blog-34995790.post-115919435914739160' source='http://www.blogger.com/feeds/34995790/posts/default/115919435914739160' type='text/html'/></entry></feed>