Configuring DSMs
186
J
UNIPER
N
ETWORKS
If you select the option
Send Syslog from vGW management server
, all
events forwarded to SIEM contain the IP address of the vGW management
server.
•
Send Syslog from Firewalls
- Distribute logging with each Firewall Security
VM providing syslog events.
Step 5
Type values for the following parameters:
a
Syslog Server
- Type the IP address of your vGW management server if you
selected to
Send Syslog from vGW management server
. Or, type the IP
address of SIEM if you selected
Send Syslog from Firewalls
.
b
Syslog Server Port
- Type the port address for syslog. This is typically port
514.
Step 6
From the
External Logging
panel, click
Save
.
Only changes made to the
External Logging
section are stored when you click
Save
. Any changes made to NetFlow require that you save using the button within
NetFlow Configuration
section.
Step 7
From the
NetFlow Configuration
panel, select the
enable
check box.
NetFlow does not support central logging from a vGW management server. From
the External Logging section, you must select the option
Send Syslog from
Firewalls
.
Step 8
Type values for the following parameters:
a
NetFlow collector address
- Type the IP address of SIEM.
b
NetFlow collector port
- Type a port address for NetFlow events.
NOTE
SIEM typically uses port 2055 for NetFlow event data on Behavioral Flow
Collectors. You must configure a different NetFlow collector port on your Juniper
Networks vGW Series Virtual Gateway for NetFlow.
Step 9
From the
NetFlow Configuration
, click
Save
.
Step 10
You are now ready to configure the log source in SIEM.
SIEM automatically detects syslog forwarded from Juniper Networks vGW. If you
want to manually configure SIEM to receive syslog events:
From the
Log Source Type
drop-down list box, select
Juniper vGW
.
For more information on configuring log sources, see the
Log Sources User Guide
.
For more information, see your Juniper Networks vGW documentation.
Summary of Contents for Security Information and Event Manager
Page 2: ......
Page 8: ......
Page 20: ......
Page 22: ......
Page 24: ......
Page 26: ......
Page 32: ......
Page 34: ......
Page 36: ......
Page 38: ......
Page 44: ......
Page 58: ......
Page 90: ......
Page 92: ......
Page 94: ......
Page 114: ......
Page 116: ......
Page 122: ......
Page 124: ......
Page 126: ...Configuring DSMs 110 FIREEYE...
Page 128: ......
Page 130: ......
Page 132: ......
Page 136: ......
Page 140: ......
Page 144: ......
Page 172: ......
Page 176: ...Configuring DSMs 160 ISC BIND...
Page 180: ......
Page 182: ......
Page 184: ......
Page 204: ......
Page 224: ......
Page 246: ......
Page 250: ......
Page 256: ......
Page 260: ......
Page 276: ......
Page 282: ......
Page 284: ......
Page 306: ......
Page 308: ......
Page 318: ......
Page 322: ......
Page 324: ......
Page 346: ......
Page 356: ......
Page 366: ......
Page 384: ......
Page 392: ......
Page 394: ......
Page 396: ......
Page 398: ......
Page 404: ......
Page 426: ......