Slashdot Mirror


Cisco Security System Shuts Out Third-Party Tools

alphadogg writes "Cisco has finally publicly acknowledged it won't add support for new third-party devices to its security information and event monitoring appliance, ending months of speculation about the future of its Monitoring, Analysis and Response System. Some claim it's the beginning of the end for MARS as a multi-vendor SIEM device. 'MARS customers can expect non-Cisco network device data and signature updates to continue for currently supported third-party systems, but no new third-party devices will be added,' Cisco declared in a statement, noting that 'Cisco MARS continues to focus on supporting Cisco devices for threat identification and mitigation.' Cisco's SIEM competitors this week have eagerly grabbed at the topic of Cisco MARS freezing third-party support because of a Gartner research memo published Oct. 29 in which analyst Mark Nicolett stated, 'Cisco has quietly begun informing its customers of a decision to freeze support for most non-Cisco event sources with its [MARS].'"

5 of 37 comments (clear)

  1. This isn't new. by Anonymous Coward · · Score: 1, Informative

    Cisco only supports Cisco. No Standard interfaces, nothing. Once they get in your shop, you are forced to buy other Cisco devices and Software to work with them.

  2. Re:Cisco won't allow legitimate owners to patch by jgasher · · Score: 2, Informative

    Very few vendors allow that. While the hardware can be resold by unauthorized resellers on what Cisco refers to as the "gray market," the software and OS licenses are non-transferable.
    Technically, anyone that buys equipment like that can't legally use it at all because they don't have a valid license for the OS.

  3. MARS is a joke by vvaduva · · Score: 4, Informative

    I've been a MARS admin/user for a few years and this is not a surprise at all. I have first generation hardware - right after the purchase, Cisco announced that they no longer provide software updates for 1st gen machines, trying to push new hardware down customers throats, so for about a year I was unable to patch or update my environment. Finally they gave in last year and started supporting both 1st and 2nd generation hardware again (I assume because customers were running away from their sinking MARS ship).

    This announcement is not a surprise at all since they've been pushing netflow like crazy, however a true event management solution should not be vendor centric to begin with. It's a pain to get MARS to take in events from Windows machines for example, or accept and manage events from other sources, so the announcement that that will no longer continue the non-existent support they had before is a non-sequitur.

    Apparently the mentality at Cisco now is that if they paint a box green and write Cisco on it, people will buy it.

  4. Re:Cisco won't allow legitimate owners to patch by amorsen · · Score: 3, Informative

    Cisco doesn't allow legitimate owners of their hardware to apply security patches without an exorbitantly expensive software subscription.

    This is actually not true. Security patches are available without a subscription. Read the security advisories published by Cisco.

    Taking advantage of the offer is sufficiently inconvenient so I don't think very many do.

    --
    Finally! A year of moderation! Ready for 2019?
  5. SenSage by Anonymous Coward · · Score: 1, Informative

    Cisco has partnered with SenSage to cover the non-Cisco log sources. DISA is implementing this solution as we speak.