10-7
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 10 Configuring Generic, Solaris, Linux, and Windows Application Hosts
Microsoft Windows Hosts
2.
Select an existing or define a new user account on the Windows host that the MARS Appliance can
use to pull event log records.
3.
Ensure that the user account has the correct credentials. Verify that the user account belongs to the
Administrator group and verity the it includes the privilege for managing and auditing security logs.
For more information, see the procedure that corresponds to the operating system running on the
host:
–
Enable Windows Pulling Using a Domain User, page 10-7
–
Enable Windows Pulling from Windows NT, page 10-7
–
Enable Windows Pulling from a Windows 2000 Server, page 10-7
–
Windows Pulling from a Windows Server 2003 or Windows XP Host, page 10-8
4.
Configure the Windows host to generate the correct event data.
5.
Identify that host in MARS so that it can correctly parse and correlate the event data. For more
information, see
Configure the MARS to Pull or Receive Windows Host Logs, page 10-9
.
6.
Specify the time interval at which the event log data should be pulled from all identified host
running Microsoft. For more information, see
Windows Event Log Pulling Time Interval, page
10-11.
Enable Windows Pulling Using a Domain User
To enable Windows pulling using a domain user (
domain\username
), for example,
CORP\syslog
, do
the following on the domain controller
before
you enable Windows pulling on your client:
Step 1
On the domain controller, click
Administrative Tools > Default Domain Security Policy > Security
Settings > Local Policies > User Rights Management
.
Step 2
Grant the permission
Manage auditing and security log
to the domain user (
domain\username
).
Enable Windows Pulling from Windows NT
To enable MARS to pull event log data from a Windows NT host, follow these steps:
Step 1
From
Start >
Programs >
Administrative Tools >
User Manager
, in the menu bar, choose
Policies
.
Step 2
In the submenu, choose
User Rights
, make sure the right of
Manage auditing and security log
is
granted to the user account used for pulling event log
records.
Step 3
In the submenu, choose
Audit
. Configure the audit policy according to your site’s security auditing
policy.
Enable Windows Pulling from a Windows 2000 Server
When there is no Active Directory Service (ADS) server sending domain information to your Windows
2000 server, you must set this property to
Disabled
on each host from which you want the MARS
Appliance to pull syslogs.
To enabled MARS to pull event log data from a Windows 2000 host, follow these steps: