Configuring DSMs
Sophos Enterprise Console
313
Once you have created your custom view, you must configure SIEM to receive
event information using the JDBC protocol.
To configure the Sophos Enterprise Console DSM with SIEM, see
Configure SIEM
to Receive Events
.
Configure SIEM to
Receive Events
To configure SIEM to access the Sophos database using the JDBC protocol:
Step 1
Log in to SIEM.
Step 2
Click the
Admin
tab.
Step 3
In the navigation menu, click
Data Sources
.
The Data Sources panel is displayed.
Step 4
Click the
Log Sources
icon.
The Log Sources window is displayed.
Step 5
Click
Add
.
The Add a log source window is displayed.
Step 6
Using the
Log Source Type
drop-down list box, select
Sophos Enterprise
Console
.
Step 7
Using the
Protocol Configuration
drop-down list box, select
JDBC
.
NOTE
You must refer to the Configure Database Settings on your Sophos Enterprise
Console to define the parameters required to configure the Sophos Enterprise
Console DSM in SIEM.
Step 8
Configure the following values:
Table 61-5
Sophos Enterprise Console JDBC Parameters
Parameter
Description
Log Source
Identifier
Type the identifier for the log source. Type the log source identifier
in the following format:
<Sophos Database>@<Sophos Database Server IP or
Host Name>
Where:
<Sophos Database>
is the database name, as entered in the
Database Name parameter.
<Sophos Database Server IP or Host Name>
is the
hostname or IP address for this log source, as entered in the IP or
Hostname parameter.
Note: When defining a name for your log source identifier, you
must use the values of the Sophos Database and Database Server
IP address or hostname from the Management Enterprise
Console.
Summary of Contents for Security Information and Event Manager
Page 2: ......
Page 8: ......
Page 20: ......
Page 22: ......
Page 24: ......
Page 26: ......
Page 32: ......
Page 34: ......
Page 36: ......
Page 38: ......
Page 44: ......
Page 58: ......
Page 90: ......
Page 92: ......
Page 94: ......
Page 114: ......
Page 116: ......
Page 122: ......
Page 124: ......
Page 126: ...Configuring DSMs 110 FIREEYE...
Page 128: ......
Page 130: ......
Page 132: ......
Page 136: ......
Page 140: ......
Page 144: ......
Page 172: ......
Page 176: ...Configuring DSMs 160 ISC BIND...
Page 180: ......
Page 182: ......
Page 184: ......
Page 204: ......
Page 224: ......
Page 246: ......
Page 250: ......
Page 256: ......
Page 260: ......
Page 276: ......
Page 282: ......
Page 284: ......
Page 306: ......
Page 308: ......
Page 318: ......
Page 322: ......
Page 324: ......
Page 346: ......
Page 356: ......
Page 366: ......
Page 384: ......
Page 392: ......
Page 394: ......
Page 396: ......
Page 398: ......
Page 404: ......
Page 426: ......