Configuring DSMs
12
CA T
ECHNOLOGIES
This section provides information on the following DSMs:
•
CA ACF2
•
CA Top Secret
CA ACF2
The CA Access Control Facility (ACF2) DSM allows you to use an IBM mainframe
to collect events and audit transactions. SIEM retrieves archived log files from a
remote host using the log file protocol and records all relevant information from the
event.
To integrate CA ACF2 events into SIEM:
1
The IBM mainframe records all security events as Service Management
Framework (SMF) records in a live repository.
2
The CA ACF2 data is extracted from the live repository using the SMF dump utility.
The SMF file contains all of the events and fields from the previous day in raw SMF
format.
3
The
QexACF2.load.trs
program pulls data from the SMF formatted file. The
QexACF2.load.trs
program only pulls the relevant events and fields for SIEM
and writes that information in a condensed format for SIEM compatibility. The
information is saved in a location accessible by SIEM.
4
SIEM uses the log file protocol source to retrieve the output file information for
SIEM on a scheduled basis. SIEM then imports and processes this file.
This document includes:
•
Configuring CA Top Secret to Integrate with SIEM
•
Pulling Data Using Log File Protocol
Configuring CA ACF2
to Integrate with
SIEM
To integrate CA ACF2 with SIEM:
Step 1
From the Enterasys Extranet website, download the following compressed file:
qexacf2_bundled.tar.gz
Step 2
On a Linux-based operating system, extract the file:
Summary of Contents for Security Information and Event Manager
Page 2: ......
Page 8: ......
Page 20: ......
Page 22: ......
Page 24: ......
Page 26: ......
Page 32: ......
Page 34: ......
Page 36: ......
Page 38: ......
Page 44: ......
Page 58: ......
Page 90: ......
Page 92: ......
Page 94: ......
Page 114: ......
Page 116: ......
Page 122: ......
Page 124: ......
Page 126: ...Configuring DSMs 110 FIREEYE...
Page 128: ......
Page 130: ......
Page 132: ......
Page 136: ......
Page 140: ......
Page 144: ......
Page 172: ......
Page 176: ...Configuring DSMs 160 ISC BIND...
Page 180: ......
Page 182: ......
Page 184: ......
Page 204: ......
Page 224: ......
Page 246: ......
Page 250: ......
Page 256: ......
Page 260: ......
Page 276: ......
Page 282: ......
Page 284: ......
Page 306: ......
Page 308: ......
Page 318: ......
Page 322: ......
Page 324: ......
Page 346: ......
Page 356: ......
Page 366: ......
Page 384: ......
Page 392: ......
Page 394: ......
Page 396: ......
Page 398: ......
Page 404: ......
Page 426: ......