Configuring DSMs
McAfee Web Gateway
205
This will give you the access handler file required to configure your McAfee Web
Gateway appliance.
access_log_file_loghandler.xml
Step 3
Log in to your McAfee Web Gateway console.
Step 4
Using the menu toolbar, click
Policy
.
NOTE
If there is an existing access log configuration in your McAfee Web Gateway
appliance, you must delete the existing access log from the Rule Set Library
before adding access_log_file_loghandler.xml.
Step 5
Click
Log Handler
.
Step 6
Using the menu tree, select
Default
.
Step 7
From the
Add
drop-down list box, select
Rule Set from Library
.
The Add a Rule Set from Library window is displayed.
Step 8
Click
Import from File button
.
Step 9
Navigate to the directory containing the access_log_file_loghandler.xml file you
downloaded in
Step 1
, and select syslog_loghandler.xml as the file to import.
When importing the rule set for access_log_file_loghandler.xml, a conflict occurs
stating the Access Log Configuration already exists in the current configuration
and a conflict solution is presented.
Step 10
If the McAfee Web Gateway appliance detects that the Access Log Configuration
already exists, select the
Conflict Solution: Change name
option presented to
resolve the rule set conflict.
For more information on resolving conflicts, see your McAfee Web Gateway
vendor documentation.
You must configure your access.log file to be pushed to an interim server on an
auto rotation. It does not matter if you push your files to the interim server based on
time or size for your access.log file. For more information on auto rotation, see
your McAfee Web Gateway vendor documentation.
NOTE
Due to the size of access.log files generated, we recommend you select the
option
GZIP files after rotation
in your McAfee Web Gate appliance.
Step 11
Click
OK
.
Step 12
Click
Save Changes
.
NOTE
By default McAfee Web Gateway is configured to write access logs to the
/opt/mwg/log/user-defined-logs/access.log/ directory.
You are now ready to configure SIEM to receive access.log files from McAfee Web
Gateway. For more information, see
Pulling Data Using the Log File Protocol
.
Summary of Contents for Security Information and Event Manager
Page 2: ......
Page 8: ......
Page 20: ......
Page 22: ......
Page 24: ......
Page 26: ......
Page 32: ......
Page 34: ......
Page 36: ......
Page 38: ......
Page 44: ......
Page 58: ......
Page 90: ......
Page 92: ......
Page 94: ......
Page 114: ......
Page 116: ......
Page 122: ......
Page 124: ......
Page 126: ...Configuring DSMs 110 FIREEYE...
Page 128: ......
Page 130: ......
Page 132: ......
Page 136: ......
Page 140: ......
Page 144: ......
Page 172: ......
Page 176: ...Configuring DSMs 160 ISC BIND...
Page 180: ......
Page 182: ......
Page 184: ......
Page 204: ......
Page 224: ......
Page 246: ......
Page 250: ......
Page 256: ......
Page 260: ......
Page 276: ......
Page 282: ......
Page 284: ......
Page 306: ......
Page 308: ......
Page 318: ......
Page 322: ......
Page 324: ......
Page 346: ......
Page 356: ......
Page 366: ......
Page 384: ......
Page 392: ......
Page 394: ......
Page 396: ......
Page 398: ......
Page 404: ......
Page 426: ......