Configuring DSMs
90
E
NTERASYS
For example, to define the local1 facility and notice level:
local1.notice @
<IP address>
Where:
<IP address>
is the IP address of the SIEM system.
Step 3
Save the file and restart syslogd.
cd /etc/rc.d
./rc.syslog stop
./rc.syslog start
Step 4
The Enterasys Dragon EMS configuration is complete.
Enterasys HiGuard
Wireless IPS
The Enterasys HiGuard Wireless IPS DSM accepts events using syslog. SIEM
records all relevant events. Before configuring the Enterasys HiGuard Wireless
IPS device in SIEM, you must configure your device to send syslog events to
SIEM.
To configure the device to send syslog events to SIEM:
Step 1
Log in to the HiGuard Wireless IPS user interface.
Step 2
In the left navigation pane, click
Syslog
, which allows the management server to
send events to designated syslog receivers.
The Syslog Configuration panel is displayed.
Step 3
In the System Integration Status section, enable syslog integration.
This allows the management server to send messages to the configured syslog
servers. By default, the management server enables syslog.
The Current Status field displays the status of the syslog server. The options are:
Running or Stopped. An error status is displayed if one of the following occurs:
•
One of the configured and enabled syslog servers includes a hostname that
cannot be resolved.
•
The management server is stopped.
•
An internal error has occurred. If this occurs, please contact Enterasys
Technical Support.
Step 4
From
Manage Syslog Servers
, click
Add
.
The Syslog Configuration window is displayed.
Step 5
Type values for the following parameters:
•
Syslog Server (IP Address/Hostname)
- Type the IP address or hostname of
the syslog server to which events should be sent.
NOTE
Configured syslog servers use the DNS names and DNS suffixes configured in
the Server initialization and Setup Wizard on the HWMH Config Shell.
Summary of Contents for Security Information and Event Manager
Page 2: ......
Page 8: ......
Page 20: ......
Page 22: ......
Page 24: ......
Page 26: ......
Page 32: ......
Page 34: ......
Page 36: ......
Page 38: ......
Page 44: ......
Page 58: ......
Page 90: ......
Page 92: ......
Page 94: ......
Page 114: ......
Page 116: ......
Page 122: ......
Page 124: ......
Page 126: ...Configuring DSMs 110 FIREEYE...
Page 128: ......
Page 130: ......
Page 132: ......
Page 136: ......
Page 140: ......
Page 144: ......
Page 172: ......
Page 176: ...Configuring DSMs 160 ISC BIND...
Page 180: ......
Page 182: ......
Page 184: ......
Page 204: ......
Page 224: ......
Page 246: ......
Page 250: ......
Page 256: ......
Page 260: ......
Page 276: ......
Page 282: ......
Page 284: ......
Page 306: ......
Page 308: ......
Page 318: ......
Page 322: ......
Page 324: ......
Page 346: ......
Page 356: ......
Page 366: ......
Page 384: ......
Page 392: ......
Page 394: ......
Page 396: ......
Page 398: ......
Page 404: ......
Page 426: ......