Configuring DSMs
Sophos PureMessage
321
Port
Type the port number used by the database server. The default
port is 1532.
The JDBC configuration port must match the listener port of the
Sophos database. The Sophos database must have incoming TCP
connections enabled to communicate with SIEM.
Username
Type the username required to access the database.
Password
Type the password required to access the database. The
password can be up to 255 characters in length.
Confirm
Password
Confirm the password required to access the database. The
confirmation password must be identical to the password entered
in the Password parameter.
Database
Instance
Optional. Type the database instance, if you have multiple SQL
server instances on your database server.
Note: If you use a non-standard port in your database
configuration, or have blocked access to port 1434 for SQL
database resolution, you must leave the Database Instance
parameter blank in your SIEM configuration.
Table Name
Type
siem_view
as the name of the table or view that includes
the event records.
Select List
Type
*
for all fields from the table or view.
You may use a comma-separated list to define specific fields from
tables or views, if required for your configuration. The list must
contain the field defined in the Compare Field parameter. The
comma-separated list can be up to 255 alphanumeric characters in
length. Also, the list may include the following special characters:
dollar sign ($), number sign (#), underscore (_), en dash (-), and
period(.).
Compare Field
Type
ID
.
The Compare Field parameter is used to identify new events
added between queries to the table.
Use Prepared
Statements
Select the check box to use prepared statements.
Prepared statements allows the JDBC protocol source to set up
the SQL statement once, and then execute the SQL statement
many times with different parameters. For security and
performance reasons, we recommend that you use prepared
statements.
Clearing this check box requires you to use an alternative method
of querying that does not use pre-compiled statements.
Start Date and
Time
Optional. Type the start date and time for database polling.
The Start Date and Time parameter must be formatted as
yyyy-MM-dd HH:mm with HH specified using a 24-hour clock. If
the Start Date and Time parameter is clear, polling begins
immediately and repeats at the specified polling interval.
Table 61-2
Sophos PureMessage JDBC Parameters (continued)
Parameter
Description
Summary of Contents for Security Information and Event Manager
Page 2: ......
Page 8: ......
Page 20: ......
Page 22: ......
Page 24: ......
Page 26: ......
Page 32: ......
Page 34: ......
Page 36: ......
Page 38: ......
Page 44: ......
Page 58: ......
Page 90: ......
Page 92: ......
Page 94: ......
Page 114: ......
Page 116: ......
Page 122: ......
Page 124: ......
Page 126: ...Configuring DSMs 110 FIREEYE...
Page 128: ......
Page 130: ......
Page 132: ......
Page 136: ......
Page 140: ......
Page 144: ......
Page 172: ......
Page 176: ...Configuring DSMs 160 ISC BIND...
Page 180: ......
Page 182: ......
Page 184: ......
Page 204: ......
Page 224: ......
Page 246: ......
Page 250: ......
Page 256: ......
Page 260: ......
Page 276: ......
Page 282: ......
Page 284: ......
Page 306: ......
Page 308: ......
Page 318: ......
Page 322: ......
Page 324: ......
Page 346: ......
Page 356: ......
Page 366: ......
Page 384: ......
Page 392: ......
Page 394: ......
Page 396: ......
Page 398: ......
Page 404: ......
Page 426: ......