Configuring DSMs
204
M
C
A
FEE
Importing the Syslog Log Handler
To Import a policy rule set for the syslog handler:
Step 1
From the Enterasys Extranet, download the following compressed file:
log_handlers.tar.gz
Step 2
Extract the file.
This will give you the syslog handler file required to configure your McAfee Web
Gateway appliance.
syslog_loghandler.xml
Step 3
Log in to your McAfee Web Gateway console.
Step 4
Using the menu toolbar, click
Policy
.
Step 5
Click
Log Handler
.
Step 6
Using the menu tree, select
Default
.
Step 7
From the
Add
drop-down list box, select
Rule Set from Library
.
The Add a Rule Set from Library window is displayed.
Step 8
Click
Import from File button
.
Step 9
Navigate to the directory containing the syslog_handler file you downloaded
in
Step 1
, and select syslog_loghandler.xml as the file to import.
NOTE
If the McAfee Web Gateway appliance detects any conflicts with the rule set, you
must resolve the conflict. For more information, see your McAfee Web Gateway
documentation.
Step 10
Click
OK
.
Step 11
Click
Save Changes
.
Step 12
You are now ready to configure the log source in SIEM.
SIEM automatically discovers syslog events from a McAfee Web Gateway
appliance.
If you want to manually configure SIEM to receive syslog events, select
McAfee Web Gateway
from the
Log Source Type
drop-down list box.
For more information on configuring log sources, see the
Log Sources User Guide
.
Configuring McAfee
Web Gateway for the
Log File Protocol
The McAfee Web Gateway appliance allows you to forward event log files to an
interim file server for retrieval by SIEM.
Step 1
From the Enterasys Extranet, download the following file:
log_handlers.tar.gz
Step 2
Extract the file.
Summary of Contents for Security Information and Event Manager
Page 2: ......
Page 8: ......
Page 20: ......
Page 22: ......
Page 24: ......
Page 26: ......
Page 32: ......
Page 34: ......
Page 36: ......
Page 38: ......
Page 44: ......
Page 58: ......
Page 90: ......
Page 92: ......
Page 94: ......
Page 114: ......
Page 116: ......
Page 122: ......
Page 124: ......
Page 126: ...Configuring DSMs 110 FIREEYE...
Page 128: ......
Page 130: ......
Page 132: ......
Page 136: ......
Page 140: ......
Page 144: ......
Page 172: ......
Page 176: ...Configuring DSMs 160 ISC BIND...
Page 180: ......
Page 182: ......
Page 184: ......
Page 204: ......
Page 224: ......
Page 246: ......
Page 250: ......
Page 256: ......
Page 260: ......
Page 276: ......
Page 282: ......
Page 284: ......
Page 306: ......
Page 308: ......
Page 318: ......
Page 322: ......
Page 324: ......
Page 346: ......
Page 356: ......
Page 366: ......
Page 384: ......
Page 392: ......
Page 394: ......
Page 396: ......
Page 398: ......
Page 404: ......
Page 426: ......