Configuring DSMs
50
O
PEN
S
OURCE
SNORT
A SIEM Open Source SNORT DSM accepts SNORT events using syslog. SIEM
records all relevant SNORT events. SourceFire’s VRT certified rules for registered
SNORT users are supported, however, Bleeding Edge, Emerging Threat, and
other third-party rule sets may not be fully supported by the Open Source SNORT
DSM.
NOTE
The below procedure applies to a system operating Red Hat Enterprise. The
procedures below may vary for other operating systems.
Before you configure SIEM to integrate with a SNORT device, you must:
Step 1
Configure SNORT on a remote system.
Step 2
Open the
snort.conf
file.
Step 3
Uncomment the following line:
output alert_syslog:LOG_AUTH LOG_INFO
Step 4
Save and exit the file.
Step 5
Open the following file:
/etc/init.d/snortd
Step 6
Add an
-s
to the following lines, as shown in the example below:
daemon /usr/sbin/snort $ALERTMODE $BINARY_LOG $NO PACKET_LOG
$DUMP_APP -D $PRINT_INTERFACE -i $i -s -u $USER -g $GROUP $CONF
-i $LOGIR/$i $PASS_FIRST
daemon /usr/sbin/snort $ALERTMODE $BINARY_LOG $NO_PACKET_LOG
$DUMP_APP -D $PRINT_INTERFACE $INTERFACE -s -u $USER -g $GROUP
$CONF -i $LOGDIR
Step 7
Save and exit the file.
Step 8
Restart SNORT:
/etc/init.d/snortd restart
Step 9
Open the
syslog.conf
file.
Step 10
Update the file to reflect the following:
auth.info
@<IP Address>
Summary of Contents for Security Information and Event Manager
Page 2: ......
Page 8: ......
Page 20: ......
Page 22: ......
Page 24: ......
Page 26: ......
Page 32: ......
Page 34: ......
Page 36: ......
Page 38: ......
Page 44: ......
Page 58: ......
Page 90: ......
Page 92: ......
Page 94: ......
Page 114: ......
Page 116: ......
Page 122: ......
Page 124: ......
Page 126: ...Configuring DSMs 110 FIREEYE...
Page 128: ......
Page 130: ......
Page 132: ......
Page 136: ......
Page 140: ......
Page 144: ......
Page 172: ......
Page 176: ...Configuring DSMs 160 ISC BIND...
Page 180: ......
Page 182: ......
Page 184: ......
Page 204: ......
Page 224: ......
Page 246: ......
Page 250: ......
Page 256: ......
Page 260: ......
Page 276: ......
Page 282: ......
Page 284: ......
Page 306: ......
Page 308: ......
Page 318: ......
Page 322: ......
Page 324: ......
Page 346: ......
Page 356: ......
Page 366: ......
Page 384: ......
Page 392: ......
Page 394: ......
Page 396: ......
Page 398: ......
Page 404: ......
Page 426: ......