Configuring DSMs
200
M
C
A
FEE
Configuring the Log Source in SIEM
You are now ready to configure the log source and protocol in SIEM:
Step 1
To configure SIEM to receive events from a McAfee ePO device, you must select
the
McAfee ePolicy Orchestrator
option from the
Log Source Type
drop-down
list box.
Step 2
To configure SNMP, you must select the same SNMP version configured on your
McAfee ePO device. From the
Protocol Configuration
drop-down list box, select
the
SNMPv2
, or
SNMPv3
option.
Step 3
If you are using SNMPv2 or SNMPv3, you must select the
Include OIDs in Event
Payload
check box.
For more information on configuring SNMP on your ePO device, see the McAfee
website at http://www.mcafee.com.
McAfee Application
/ Change Control
A SIEM McAfee Application / Change Control DSM accepts change control events
using Java Database Connectivity (JDBC). SIEM records all relevant McAfee
Application / Change Control events. This document includes information on
configuring SIEM to access the database containing events using the JDBC
protocol.
To configure SIEM:
Step 1
Log in to SIEM.
Step 2
Click the
Admin
tab.
Step 3
In the navigation menu, click
Data Sources
.
The Data Sources panel is displayed.
Step 4
Click the
Log Sources
icon.
The Log Sources window is displayed.
Step 5
Click
Add
.
The Add a log source window is displayed.
Step 6
Using the
Log Source Type
drop-down list box, select
McAfee Application /
Change Control
.
Step 7
Using the
Protocol Configuration
drop-down list box, select
JDBC
.
You must refer to the Configure Database Settings on your ePO Management
Console to configure the McAfee Application / Change Control DSM in SIEM.
Step 8
Configure the following values:
Summary of Contents for Security Information and Event Manager
Page 2: ......
Page 8: ......
Page 20: ......
Page 22: ......
Page 24: ......
Page 26: ......
Page 32: ......
Page 34: ......
Page 36: ......
Page 38: ......
Page 44: ......
Page 58: ......
Page 90: ......
Page 92: ......
Page 94: ......
Page 114: ......
Page 116: ......
Page 122: ......
Page 124: ......
Page 126: ...Configuring DSMs 110 FIREEYE...
Page 128: ......
Page 130: ......
Page 132: ......
Page 136: ......
Page 140: ......
Page 144: ......
Page 172: ......
Page 176: ...Configuring DSMs 160 ISC BIND...
Page 180: ......
Page 182: ......
Page 184: ......
Page 204: ......
Page 224: ......
Page 246: ......
Page 250: ......
Page 256: ......
Page 260: ......
Page 276: ......
Page 282: ......
Page 284: ......
Page 306: ......
Page 308: ......
Page 318: ......
Page 322: ......
Page 324: ......
Page 346: ......
Page 356: ......
Page 366: ......
Page 384: ......
Page 392: ......
Page 394: ......
Page 396: ......
Page 398: ......
Page 404: ......
Page 426: ......