10-9
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 10 Configuring Generic, Solaris, Linux, and Windows Application Hosts
Microsoft Windows Hosts
Example Configuration of Event Log Security Privileges on a Microsoft Windows 2003 Server
The following procedure is an example of the
Microsoft Configure Event Log Security Locally
procedure. Complete this procedure to give the pulling account the following event log privileges:
•
Read security event log
•
Read application event log
•
Read system event log
Warning
If you use Registry Editor incorrectly, you may cause serious problems that may require you to
reinstall your operating system. Microsoft Corporation or Cisco Systems, Inc. cannot guarantee that
you can solve problems that result from using Registry Editor incorrectly. Use Registry Editor at your
own risk.
Step 1
Launch the Microsoft Windows regedit program. (Enter
regedit
from the
Start > Run
menu)
Step 2
Append
(A;;0x1;;;
sid-of-the-pulling-account
)
to the end of the following registry keys:
•
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security\CustomSD
•
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\CustomSD
•
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\CustomSD
Use the Security Identifier [SID] of the pulling account to replace the variable
sid-of-the-pulling-account
. For example, if the pulling account's SID is
S-1-5-21-1801671234-2025421234-839521234-123456
and the original value of CustomSD is as
follows:
O:BAG:SYD:(D;;0xf0007;;;AN)(D;;0xf0007;;;BG)(A;;0xf0007;;;SY)(A;;0x7;;;BA)(A;;0x7;;;SO)
(A;;0x3;;;IU)(A;;0x3;;;SU)(A;;0x3;;;S-1-5-3)
Change the CustomSD registry key as follows:
O:BAG:SYD:(D;;0xf0007;;;AN)(D;;0xf0007;;;BG)(A;;0xf0007;;;SY)(A;;0x7;;;BA)(A;;0x7;;;SO)
(A;;0x3;;;IU)(A;;0x3;;;SU)(A;;0x3;;;S-1-5-3)(A;;0x1;;;S-1-5-21-1801671234-2025421234-83952
1234-123456)
Step 3
Save changes and exit regedit.
Configure the MARS to Pull or Receive Windows Host Logs
Once you’ve prepared the Microsoft Windows host, you must identify that host in MARS and identify
whether the push or pull method is being used on that host.
To configure the MARS Appliance to either pull or receive logs, follow these steps:
Step 1
Select
Admin >
Security and Monitor Devices >
Add
Step 2
From the
Device Type
list, select
Add SW Security apps on a new host
or Add
SW security apps on
existing host.
Step 3
Enter the
Device Name
and
IP addresses
if adding a new host.
Step 4
Select the
Operating System
>
Windows
from the list.