Configuring DSMs
33
I
MPERVA
S
ECURE
S
PHERE
The SIEM Imperva SecureSphere DSM accepts events using syslog. SIEM
records all relevant events. Before configuring an Imperva SecureSphere device in
SIEM, you must configure your device to send syslog events to SIEM.
To configure the device to send syslog events to SIEM:
Step 1
Log in to your SecureSphere device user interface using administrative privileges.
Step 2
Click the
Policies
tab.
Step 3
Click the
Action Sets
tab.
Step 4
To generate events for each alert generated by the SecureSphere device:
a
Create a new action set named
q1labs_alerts
.
b
Click the arrow beside System Log to move the action interface to the
Selected
Actions
list.
c
Expand the
System Log
action group.
d
In the
Action Name
field, type
q1labs_syslog_alerts
.
e
Configure the following parameters:
-
Syslog host
- Type the IP address of the SIEM system to which you want to
send events.
-
Syslog log level
- Select
INFO
.
-
Message
- You must type the following message as a pipe separated
continuous string:
DeviceType=ImpervaSecuresphere Alert|an=$!{Alert.alertMetadat
a.alertName}|at=Securesphere Alert|ad=$!{Alert.description}|s
p=$!{Event.sourceInfo.sourcePort}|s=$!{Event.sourceInfo.sourc
eIp}|d=$!{Event.destInfo.serverIp}|dp=$!{Event.destInfo.serve
rPort}|u=$!{Alert.username}|g=$!{Alert.serverGroupName}
f
Select the
Run on Every Event
check box.
g
Click
Save
.
Step 5
To enable the
q1labs_alerts
action created above, you must edit your policies
to use the alerts action.
The below procedure details the steps to configure the action for a firewall policy.
Repeat this procedure for all required policies.
Summary of Contents for Security Information and Event Manager
Page 2: ......
Page 8: ......
Page 20: ......
Page 22: ......
Page 24: ......
Page 26: ......
Page 32: ......
Page 34: ......
Page 36: ......
Page 38: ......
Page 44: ......
Page 58: ......
Page 90: ......
Page 92: ......
Page 94: ......
Page 114: ......
Page 116: ......
Page 122: ......
Page 124: ......
Page 126: ...Configuring DSMs 110 FIREEYE...
Page 128: ......
Page 130: ......
Page 132: ......
Page 136: ......
Page 140: ......
Page 144: ......
Page 172: ......
Page 176: ...Configuring DSMs 160 ISC BIND...
Page 180: ......
Page 182: ......
Page 184: ......
Page 204: ......
Page 224: ......
Page 246: ......
Page 250: ......
Page 256: ......
Page 260: ......
Page 276: ......
Page 282: ......
Page 284: ......
Page 306: ......
Page 308: ......
Page 318: ......
Page 322: ......
Page 324: ......
Page 346: ......
Page 356: ......
Page 366: ......
Page 384: ......
Page 392: ......
Page 394: ......
Page 396: ......
Page 398: ......
Page 404: ......
Page 426: ......