O'Reilly logo

Security Monitoring with Cisco Security MARS by Greg Kellogg, Gary Halleen

Stay ahead with the world's most comprehensive technology and business learning platform.

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, tutorials, and more.

Start Free Trial

No credit card required

Appendix A. Querying the Archive

Chapter 7, “Archiving and Disaster Recovery,” describes the Cisco Security Monitoring, Analysis, and Response System (CS-MARS) archiving capabilities. The archives provide critical backup and recovery functionality, as well as the capability to run queries against the archives from within the CS-MARS user interface. Although this functionality is handy, sometimes you might find the need to use other tools to query the data.

If you have properly configured archiving, MARS will regularly write all event data to the Network File System (NFS) archive within minutes of being processed by MARS. This data is easily accessible through the command line from the host on which the data sits.

You might need to manipulate ...

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, interactive tutorials, and more.

Start Free Trial

No credit card required