Configuring DSMs
86
E
NTERASYS
You are now ready to configure the log source SNMP protocol in SIEM. See
Configuring SIEM
.
For information on configuring SNMP in SIEM, see the
Log Sources User Guide
.
Creating a Policy
with a Syslog
Notification Rule
This procedure describes how to configure an Alarm Tool policy using a Syslog
notification rule in the Log Event Extended Format (LEEF) message format. LEEF
is the preferred message format for sending notifications to Dragon Network
Defense when the notification rate is very high or when IPv6 addresses are
displayed.
If you prefer not to use syslog notifications in LEEF format, refer to your
Enterasys
IPS documentation
for more information.
NOTE
Use SNMPv3 notification rules if you need to transfer PDATA, which is a binary
data element. Do not use a Syslog notification rule.
To configure Enterasys Dragon with an Alarm Tool policy using a syslog notification
rule:
Step 1
Log in to the Enterasys Dragon EMS.
Step 2
Click the
Alarm Tool
icon.
Step 3
Configure the Alarm Tool Policy:
a
In the
Alarm Tool Policy View > Custom Policies
menu tree, right-click and
select
Add Alarm Tool Policy
.
The Add Alarm Tool Policy window is displayed.
b
In the
Add Alarm Tool Policy
field, type a policy name.
For example:
Enterasys Networks
c
Click
OK
.
d
In the menu tree, select Enterasys Networks.
Step 4
To configure the event group:
a
Click the
Events Group
tab.
b
Click
New
.
The Event Group Editor is displayed.
c
Select the event group or individual events to monitor.
d
Click
Add
.
A prompt is displayed.
e
Click
Yes
.
f
In the right column of the Event Group Editor, type
Dragon-Events
.
Summary of Contents for Security Information and Event Manager
Page 2: ......
Page 8: ......
Page 20: ......
Page 22: ......
Page 24: ......
Page 26: ......
Page 32: ......
Page 34: ......
Page 36: ......
Page 38: ......
Page 44: ......
Page 58: ......
Page 90: ......
Page 92: ......
Page 94: ......
Page 114: ......
Page 116: ......
Page 122: ......
Page 124: ......
Page 126: ...Configuring DSMs 110 FIREEYE...
Page 128: ......
Page 130: ......
Page 132: ......
Page 136: ......
Page 140: ......
Page 144: ......
Page 172: ......
Page 176: ...Configuring DSMs 160 ISC BIND...
Page 180: ......
Page 182: ......
Page 184: ......
Page 204: ......
Page 224: ......
Page 246: ......
Page 250: ......
Page 256: ......
Page 260: ......
Page 276: ......
Page 282: ......
Page 284: ......
Page 306: ......
Page 308: ......
Page 318: ......
Page 322: ......
Page 324: ......
Page 346: ......
Page 356: ......
Page 366: ......
Page 384: ......
Page 392: ......
Page 394: ......
Page 396: ......
Page 398: ......
Page 404: ......
Page 426: ......