Configuring DSMs
75
U
NIVERSAL
DSM
SIEM collects and correlates events from network infrastructure and security
devices. Once the events are collected and before the correlation can begin, the
individual events from these devices must be properly parsed to determine the
event name, IP addresses, protocol, and ports. For common network devices
(such as, NetScreen Firewalls) predefined DSMs have been engineered into SIEM
to properly parse all event messages from the respective devices. Once the events
from a device have been parsed by the DSM, SIEM can continue to correlate
events into offenses.
If an enterprise network has one or more network or security devices that are not
officially supported (no specific DSM for the device exists), you can use the
Universal DSM. The Universal DSM allows you to forward events and messages
from unsupported devices to SIEM for correlation. SIEM integrates with many
common protocol sources using the Universal DSM.
For more information about log source protocols, see the
Log Sources User Guide
.
To configure the Universal DSM, you must use device extensions to associate a
Universal DSM to devices. Before you define device extension information using
the log sources window in the Admin tab, you must create an extensions document
for the log source. For information about device extensions, see the
Log Sources
User Guide
.
Summary of Contents for Security Information and Event Manager
Page 2: ......
Page 8: ......
Page 20: ......
Page 22: ......
Page 24: ......
Page 26: ......
Page 32: ......
Page 34: ......
Page 36: ......
Page 38: ......
Page 44: ......
Page 58: ......
Page 90: ......
Page 92: ......
Page 94: ......
Page 114: ......
Page 116: ......
Page 122: ......
Page 124: ......
Page 126: ...Configuring DSMs 110 FIREEYE...
Page 128: ......
Page 130: ......
Page 132: ......
Page 136: ......
Page 140: ......
Page 144: ......
Page 172: ......
Page 176: ...Configuring DSMs 160 ISC BIND...
Page 180: ......
Page 182: ......
Page 184: ......
Page 204: ......
Page 224: ......
Page 246: ......
Page 250: ......
Page 256: ......
Page 260: ......
Page 276: ......
Page 282: ......
Page 284: ......
Page 306: ......
Page 308: ......
Page 318: ......
Page 322: ......
Page 324: ......
Page 346: ......
Page 356: ......
Page 366: ......
Page 384: ......
Page 392: ......
Page 394: ......
Page 396: ......
Page 398: ......
Page 404: ......
Page 426: ......