Configuring DSMs
57
S
AMHAIN
L
ABS
The Samhain Labs Host-Based Intrusion Detection System (HIDS) monitors
changes to files on the system. The Samhain HIDS DSM supports Samhain
version 2.4 when used for File Integrity Monitoring (FIM).
You can configure the Samhain HIDS DSM to accept one of the following log
types:
•
Using Syslog
•
Using JDBC
Using Syslog
Before you configure SIEM to integrate with Samhain HIDS using syslog, you must
configure the Samhain HIDS system to forward logs to your SIEM system.
NOTE
The following procedure is based on the default samhainrc file. If the samhainrc
file has been modified, some values (such as syslog facility) may be different.
To configure Samhain HIDS to forward logs using syslog to SIEM:
Step 1
Log in to Samhain HIDS from the command line interface.
Step 2
Open the following file:
/etc/samhainrc
Step 3
Remove the comment marker (
#
) from the following line:
SetLogServer=info
Step 4
Save and exit the file.
Alerts are sent to the local system’s syslog.
Step 5
Open the following file:
/etc/syslog.conf
Step 6
Add the following line:
local2.* @<IP Address>
Where
<IP Address>
is the IP address of the Event Collector.
Step 7
Save and exit the file.
Summary of Contents for Security Information and Event Manager
Page 2: ......
Page 8: ......
Page 20: ......
Page 22: ......
Page 24: ......
Page 26: ......
Page 32: ......
Page 34: ......
Page 36: ......
Page 38: ......
Page 44: ......
Page 58: ......
Page 90: ......
Page 92: ......
Page 94: ......
Page 114: ......
Page 116: ......
Page 122: ......
Page 124: ......
Page 126: ...Configuring DSMs 110 FIREEYE...
Page 128: ......
Page 130: ......
Page 132: ......
Page 136: ......
Page 140: ......
Page 144: ......
Page 172: ......
Page 176: ...Configuring DSMs 160 ISC BIND...
Page 180: ......
Page 182: ......
Page 184: ......
Page 204: ......
Page 224: ......
Page 246: ......
Page 250: ......
Page 256: ......
Page 260: ......
Page 276: ......
Page 282: ......
Page 284: ......
Page 306: ......
Page 308: ......
Page 318: ......
Page 322: ......
Page 324: ......
Page 346: ......
Page 356: ......
Page 366: ......
Page 384: ......
Page 392: ......
Page 394: ......
Page 396: ......
Page 398: ......
Page 404: ......
Page 426: ......