Showing posts with label CS-MARS Custom Parser. Show all posts
Showing posts with label CS-MARS Custom Parser. Show all posts

Thursday, April 19, 2007

XP Firewall Custom Parser

Now before i start, NO NO NO i do not recommend configuring this on all the desktops in your network!

I have created this parser basically as a sample exercise, for those people getting to know MARS, and the custom parser functionality.


Without having to have vendor X,Y,Z`s appliance or application on the network etc, you can simply install the PNLog Agent on your XP machine (sorry no Vista, i`ve refrained for now, due to colleagues screams in the office), create the simple parser, and test the functionality.

This is available in the MARS User Group Files Section, and i`ll provide a direct link next week.


Wednesday, March 14, 2007

New Custom Parser Demo Now Available


Theres a new Cisco MARS Parser flash demo available on Demolabs.

Now to cut a long story short, i`ve decided to split the Parser template demo, into 2 parts.

Part 2, which is available now, is what i would term the BASIC level demo. This doesn`t go into too much detail on actually creating the Parser Patterns, but it useful for getting a basic understanding of what the Custom Parser functionality is for.

Part 3, which should hopefully be ready by the end of the week, is what i would call the ADVANCED demo. A Log Template is created from start to finish.

Monday, February 26, 2007

New Custom Parser Demo available on demolabs.co.uk

There is a new CS-MARS demo available on the Satisnet Demo Website, Demolabs.co.uk


This demo is the first in a series of Custom Parser Demos

I hope to write a couple of articles on the Custom Parser very soon, but the above demo is about as basic as the custom parser gets.

We can simply fire syslog at MARS and do a keyword search on unknown events. (In fact the demo is a little smarter in that we define a custom device first, and thus we could add more similar devices, and report on them individually)