Configuring DSMs
220
M
ICROSOFT
Configuring
Microsoft IIS Using
the Adaptive Log
Exporter
The Adaptive Log Exporter is a stand-alone application that allows you to integrate
device logs or application event data with SIEM. The Adaptive Log Export supports
NCSA, IIS, and W3C active log formats.
To integrate the Adaptive Log Exporter with Microsoft IIS, perform the following
steps:
Step 1
Log in to your Microsoft Information Services (IIS) Manager.
Step 2
In the IIS Manager menu tree, expand
Local Computer
.
Step 3
Select
Web Sites
.
Step 4
Right-click on
Default Web Site
and select
Properties
.
The Web Sites Properties window is displayed.
Step 5
From the
Active Log Format
drop-down list box, select one of the following:
•
Select
NCSA
. Go to
Step 9
.
•
Select
IIS
. Go to
Step 9
.
•
Select
W3C
. Go to
Step 6
.
Step 6
Click
Properties
.
The Properties window is displayed.
Step 7
Click the
Advanced
tab.
Step 8
From the list of properties, select all event properties that you want to apply to the
Microsoft IIS event log. The selected properties must include the following:
a
Select the
Method (cs-method)
check box.
b
Select the
Protocol Version (cs-version)
check box.
Step 9
Click
OK
.
Step 10
You are now ready to configure the Adaptive Log Exporter.
For more information on installing and configuring Microsoft IIS for the Adaptive
Log Exporter, see the
Adaptive Log Exporter User Guide
.
Microsoft ISA
A SIEM Microsoft Internet and Acceleration (ISA) DSM accepts events using
syslog. You can integrate Microsoft ISA Server with SIEM using the Adaptive Log
Exporter. For more information on the Adaptive Log Exporter, see the
Adaptive
Log Exporter Users Guide
.
You are now ready to configure the log source in SIEM.
To configure SIEM to receive events from a Microsoft ISA Server:
From the
Log Source Type
drop-down list box, select the
Microsoft ISA
option.
For more information on configuring devices, see the
Log Sources User Guide
.
Summary of Contents for Security Information and Event Manager
Page 2: ......
Page 8: ......
Page 20: ......
Page 22: ......
Page 24: ......
Page 26: ......
Page 32: ......
Page 34: ......
Page 36: ......
Page 38: ......
Page 44: ......
Page 58: ......
Page 90: ......
Page 92: ......
Page 94: ......
Page 114: ......
Page 116: ......
Page 122: ......
Page 124: ......
Page 126: ...Configuring DSMs 110 FIREEYE...
Page 128: ......
Page 130: ......
Page 132: ......
Page 136: ......
Page 140: ......
Page 144: ......
Page 172: ......
Page 176: ...Configuring DSMs 160 ISC BIND...
Page 180: ......
Page 182: ......
Page 184: ......
Page 204: ......
Page 224: ......
Page 246: ......
Page 250: ......
Page 256: ......
Page 260: ......
Page 276: ......
Page 282: ......
Page 284: ......
Page 306: ......
Page 308: ......
Page 318: ......
Page 322: ......
Page 324: ......
Page 346: ......
Page 356: ......
Page 366: ......
Page 384: ......
Page 392: ......
Page 394: ......
Page 396: ......
Page 398: ......
Page 404: ......
Page 426: ......