Configuring DSMs
320
S
OPHOS
Configure SIEM to Receive Events From Sophos PureMessage for Microsoft
Exchange
To configure SIEM to access the Sophos PureMessage database using the JDBC
protocol:
Step 1
Log in to SIEM.
Step 2
Click the
Admin
tab.
Step 3
In the navigation menu, click
Data Sources
.
The Data Sources panel is displayed.
Step 4
Click the
Log Sources
icon.
The Log Sources window is displayed.
Step 5
Click
Add
.
The Add a log source window is displayed.
Step 6
From the
Log Source Type
drop-down list box, select
Sophos PureMessage
.
Step 7
From the
Protocol Configuration
drop-down list box, select
JDBC
.
NOTE
You must refer to the Configure Database Settings on your Sophos PureMessage
to define the parameters required to configure the Sophos PureMessage DSM in
SIEM.
Step 8
Configure the following values:
Table 61-2
Sophos PureMessage JDBC Parameters
Parameter
Description
Log Source
Identifier
Type the identifier for the log source. Type the log source identifier
in the following format:
<Sophos PureMessage Database>@<Sophos PureMessage
Database Server IP or Host Name>
Where:
<Sophos PureMessage Database>
is the database name, as
entered in the Database Name parameter.
<Sophos PureMessage Database Server IP or Host
Name>
is the hostname or IP address for this log source, as
entered in the IP or Hostname parameter.
When defining a name for your log source identifier, you must use
the values of the Database and Database Server IP address or
hostname of the Sophos PureMessage device.
Database Type
From the drop-down list box, select
Postgres
.
Database Name
Type
pmx_quarantine
.
IP or Hostname
Type the IP address or host name of the Sophos PureMessage
server.
Summary of Contents for Security Information and Event Manager
Page 2: ......
Page 8: ......
Page 20: ......
Page 22: ......
Page 24: ......
Page 26: ......
Page 32: ......
Page 34: ......
Page 36: ......
Page 38: ......
Page 44: ......
Page 58: ......
Page 90: ......
Page 92: ......
Page 94: ......
Page 114: ......
Page 116: ......
Page 122: ......
Page 124: ......
Page 126: ...Configuring DSMs 110 FIREEYE...
Page 128: ......
Page 130: ......
Page 132: ......
Page 136: ......
Page 140: ......
Page 144: ......
Page 172: ......
Page 176: ...Configuring DSMs 160 ISC BIND...
Page 180: ......
Page 182: ......
Page 184: ......
Page 204: ......
Page 224: ......
Page 246: ......
Page 250: ......
Page 256: ......
Page 260: ......
Page 276: ......
Page 282: ......
Page 284: ......
Page 306: ......
Page 308: ......
Page 318: ......
Page 322: ......
Page 324: ......
Page 346: ......
Page 356: ......
Page 366: ......
Page 384: ......
Page 392: ......
Page 394: ......
Page 396: ......
Page 398: ......
Page 404: ......
Page 426: ......