Configuring DSMs
316
S
OPHOS
•
Sophos PureMessage for Linux
- Stores events in a PostgreSQL database
specified as pmx_quarantine.
This section provides information on the following:
•
Integrating SIEM with Sophos PureMessage for Microsoft Exchange
•
Integrating SIEM with Sophos PureMessage for Linux
Integrating SIEM with
Sophos
PureMessage for
Microsoft Exchange
To integrate SIEM with Sophos PureMessage for Microsoft Exchange:
Step 1
Log in to the Microsoft SQL Server command line interface (CLI):
osql -E -S localhost\sophos
Step 2
Type which database you want to integrate with SIEM:
use savexquar;
go
Step 3
Type the following command to create a SIEM view in your Sophos database to
support SIEM:
create view siem_view as select 'Windows PureMessage' as
application, id, reason, timecreated, emailonly as sender,
filesize, subject, messageid, filename from dbo.quaritems,
dbo.quaraddresses where ItemID = ID and Field = 76;
Go
Once you have created your SIEM view, you must configure SIEM to receive event
information using the JDBC protocol.
To configure the Sophos PureMessage DSM with SIEM, see
Configure SIEM to
Receive Events From Sophos PureMessage for Microsoft Exchange
.
Configure SIEM to Receive Events From Sophos PureMessage for Microsoft
Exchange
To configure SIEM to access the Sophos PureMessage for Microsoft Exchange
database using the JDBC protocol:
Step 1
Log in to SIEM.
Step 2
Click the
Admin
tab.
Step 3
In the navigation menu, click
Data Sources
.
The Data Sources panel is displayed.
Step 4
Click the
Log Sources
icon.
The Log Sources window is displayed.
Step 5
Click
Add
.
The Add a log source window is displayed.
Summary of Contents for Security Information and Event Manager
Page 2: ......
Page 8: ......
Page 20: ......
Page 22: ......
Page 24: ......
Page 26: ......
Page 32: ......
Page 34: ......
Page 36: ......
Page 38: ......
Page 44: ......
Page 58: ......
Page 90: ......
Page 92: ......
Page 94: ......
Page 114: ......
Page 116: ......
Page 122: ......
Page 124: ......
Page 126: ...Configuring DSMs 110 FIREEYE...
Page 128: ......
Page 130: ......
Page 132: ......
Page 136: ......
Page 140: ......
Page 144: ......
Page 172: ......
Page 176: ...Configuring DSMs 160 ISC BIND...
Page 180: ......
Page 182: ......
Page 184: ......
Page 204: ......
Page 224: ......
Page 246: ......
Page 250: ......
Page 256: ......
Page 260: ......
Page 276: ......
Page 282: ......
Page 284: ......
Page 306: ......
Page 308: ......
Page 318: ......
Page 322: ......
Page 324: ......
Page 346: ......
Page 356: ......
Page 366: ......
Page 384: ......
Page 392: ......
Page 394: ......
Page 396: ......
Page 398: ......
Page 404: ......
Page 426: ......