Configuring DSMs
Sophos Enterprise Console
311
Password
Type the password required to access the database. The
password can be up to 255 characters in length.
Confirm
Password
Confirm the password required to access the database. The
confirmation password must be identical to the password entered
in the Password parameter.
Authentication
Domain
If you select MSDE as the Database Type and the database is
configured for Windows, you must define a Window Authentication
Domain. Otherwise, leave this field blank.
Database
Instance
Optional. Type the database instance, if you have multiple SQL
server instances on your database server.
Note: If you use a non-standard port in your database
configuration, or have blocked access to port 1434 for SQL
database resolution, you must leave the Database Instance
parameter blank in your SIEM configuration.
Table Name
Type
vEventsCommonData
as the name of the table or view that
includes the event records.
Select List
Type
*
for all fields from the table or view.
You may use a comma-separated list to define specific fields from
tables or views, if required for your configuration. The list must
contain the field defined in the Compare Field parameter. The
comma-separated list can be up to 255 alphanumeric characters in
length. Also, the list may include the following special characters:
dollar sign ($), number sign (#), underscore (_), en dash (-), and
period(.).
Compare Field
Type
InsertedAt
as the compare field. The compare field is used
to identify new events added between queries to the table.
Start Date and
Time
Optional. Type the start date and time for database polling.
The Start Date and Time parameter must be formatted as
yyyy-MM-dd HH:mm with HH specified using a 24 hour clock. If the
start date or time is clear, polling begins immediately and repeats
at the specified polling interval.
Polling Interval
Type the polling interval, which is the amount of time between
queries to the event table. The default polling interval is 10
seconds.
You may define a longer polling interval by appending H for hours
or M for minutes to the numeric value. The maximum polling
interval is 1 week in any time format. Numeric values entered
without an H or M poll in seconds.
EPS Throttle
Type the number of Event Per Second (EPS) that you do not want
this protocol to exceed. The default value is 20000 EPS.
Table 61-4
Sophos Enterprise Console JDBC Parameters (continued)
Parameter
Description
Summary of Contents for Security Information and Event Manager
Page 2: ......
Page 8: ......
Page 20: ......
Page 22: ......
Page 24: ......
Page 26: ......
Page 32: ......
Page 34: ......
Page 36: ......
Page 38: ......
Page 44: ......
Page 58: ......
Page 90: ......
Page 92: ......
Page 94: ......
Page 114: ......
Page 116: ......
Page 122: ......
Page 124: ......
Page 126: ...Configuring DSMs 110 FIREEYE...
Page 128: ......
Page 130: ......
Page 132: ......
Page 136: ......
Page 140: ......
Page 144: ......
Page 172: ......
Page 176: ...Configuring DSMs 160 ISC BIND...
Page 180: ......
Page 182: ......
Page 184: ......
Page 204: ......
Page 224: ......
Page 246: ......
Page 250: ......
Page 256: ......
Page 260: ......
Page 276: ......
Page 282: ......
Page 284: ......
Page 306: ......
Page 308: ......
Page 318: ......
Page 322: ......
Page 324: ......
Page 346: ......
Page 356: ......
Page 366: ......
Page 384: ......
Page 392: ......
Page 394: ......
Page 396: ......
Page 398: ......
Page 404: ......
Page 426: ......