Configuring DSMs
314
S
OPHOS
Database Type
From the drop-down list box, select
MSDE
.
Database Name
Type the exact name of the Sophos database.
IP or Hostname
Type the IP address or host name of the Sophos SQL Server.
Port
Type the port number used by the database server. The default
port for MSDE is 1433.
The JDBC configuration port must match the listener port of the
Sophos database. The Sophos database must have incoming TCP
connections enabled to communicate with SIEM.
Note: If you define a Database Instance when using MSDE as the
database type, you must leave the Port parameter blank in your
SIEM configuration.
Username
Type the username required to access the database.
Password
Type the password required to access the database. The
password can be up to 255 characters in length.
Confirm
Password
Confirm the password required to access the database. The
confirmation password must be identical to the password entered
in the Password parameter.
Authentication
Domain
If you select MSDE as the Database Type and the database is
configured for Windows, you must define a Window Authentication
Domain. Otherwise, leave this field blank.
Database
Instance
Optional. Type the database instance, if you have multiple SQL
server instances on your database server.
Note: If you use a non-standard port in your database
configuration, or have blocked access to port 1434 for SQL
database resolution, you must leave the Database Instance
parameter blank in your SIEM configuration.
Table Name
Type
threats_view
as the name of the table or view that includes
the event records.
Select List
Type
*
for all fields from the table or view.
You may use a comma-separated list to define specific fields from
tables or views, if required for your configuration. The list must
contain the field defined in the Compare Field parameter. The
comma-separated list can be up to 255 alphanumeric characters in
length. Also, the list may include the following special characters:
dollar sign ($), number sign (#), underscore (_), en dash (-), and
period(.).
Compare Field
Type
ThreatInstanceID
as the compare field. The compare field is
used to identify new events added between queries to the table.
Start Date and
Time
Optional. Type the start date and time for database polling.
The Start Date and Time parameter must be formatted as
yyyy-MM-dd HH:mm with HH specified using a 24 hour clock. If the
start date or time is clear, polling begins immediately and repeats
at the specified polling interval.
Table 61-5
Sophos Enterprise Console JDBC Parameters (continued)
Parameter
Description
Summary of Contents for Security Information and Event Manager
Page 2: ......
Page 8: ......
Page 20: ......
Page 22: ......
Page 24: ......
Page 26: ......
Page 32: ......
Page 34: ......
Page 36: ......
Page 38: ......
Page 44: ......
Page 58: ......
Page 90: ......
Page 92: ......
Page 94: ......
Page 114: ......
Page 116: ......
Page 122: ......
Page 124: ......
Page 126: ...Configuring DSMs 110 FIREEYE...
Page 128: ......
Page 130: ......
Page 132: ......
Page 136: ......
Page 140: ......
Page 144: ......
Page 172: ......
Page 176: ...Configuring DSMs 160 ISC BIND...
Page 180: ......
Page 182: ......
Page 184: ......
Page 204: ......
Page 224: ......
Page 246: ......
Page 250: ......
Page 256: ......
Page 260: ......
Page 276: ......
Page 282: ......
Page 284: ......
Page 306: ......
Page 308: ......
Page 318: ......
Page 322: ......
Page 324: ......
Page 346: ......
Page 356: ......
Page 366: ......
Page 384: ......
Page 392: ......
Page 394: ......
Page 396: ......
Page 398: ......
Page 404: ......
Page 426: ......