Configuring DSMs
54
R
ADWARE
D
EFENSE
P
RO
A SIEM Radware DefensePro DSM accepts events using syslog. Event traps can
also be mirrored to a syslog server.
Before you configure SIEM to integrate with a Radware DefensePro device, you
must configure your Radware DefensePro device to integrate with SIEM. You must
configure the appropriate information using the
Device > Trap and SMTP option
.
Any traps generated by the Radware device are mirrored to the specified syslog
server. The current Radware Syslog server enables you to define the status and
the event log server address.
You can also define additional notification criteria, such as Facility and Severity,
which are expressed by numerical values:
•
Facility is a user-defined value indicating the type of device used by the sender.
This criteria is applied when the device sends syslog messages. The default
value is 21, meaning
Local Use 6
.
•
Severity indicates the importance or impact of the reported event. The Severity
is determined dynamically by the device for each message sent.
In the Security Settings window, you must enable security reporting using the
connect and protect/security settings. You must enable security reports to syslog
and configure the severity (syslog risk).
You are now ready to configure the log source in SIEM interface.
To configure SIEM to receive events from a Radware DefensePro device:
From the
Log Source Type
drop-down list box, select the
Radware
DefensePro
option.
For more information on configuring log sources and protocols, see the
Log
Sources User Guide
.
For more information about the Radware DefensePro device, see your vendor
documentation.
Summary of Contents for Security Information and Event Manager
Page 2: ......
Page 8: ......
Page 20: ......
Page 22: ......
Page 24: ......
Page 26: ......
Page 32: ......
Page 34: ......
Page 36: ......
Page 38: ......
Page 44: ......
Page 58: ......
Page 90: ......
Page 92: ......
Page 94: ......
Page 114: ......
Page 116: ......
Page 122: ......
Page 124: ......
Page 126: ...Configuring DSMs 110 FIREEYE...
Page 128: ......
Page 130: ......
Page 132: ......
Page 136: ......
Page 140: ......
Page 144: ......
Page 172: ......
Page 176: ...Configuring DSMs 160 ISC BIND...
Page 180: ......
Page 182: ......
Page 184: ......
Page 204: ......
Page 224: ......
Page 246: ......
Page 250: ......
Page 256: ......
Page 260: ......
Page 276: ......
Page 282: ......
Page 284: ......
Page 306: ......
Page 308: ......
Page 318: ......
Page 322: ......
Page 324: ......
Page 346: ......
Page 356: ......
Page 366: ......
Page 384: ......
Page 392: ......
Page 394: ......
Page 396: ......
Page 398: ......
Page 404: ......
Page 426: ......