Configuring DSMs
CA ACF2
35
Where:
<IPADDR>
is the IP address or host name of the interim FTP server to receive
the output file.
<USER>
is the user name required to access the interim FTP server.
<PASSWORD>
is the password required to access the interim FTP server.
<THEIPOFTHEMAINFRAMEDEVICE>
is the destination of the mainframe or
interim FTP server receiving the output.
For example:
PUT 'Q1JACK.QEXACF2.OUTPUT.C320' /192.168.1.101/ACF2/QEXACF2.
OUTPUT.C320
<QEXOUTDSN>
is the name of the output file saved to the interim FTP server.
You are now ready to configure the Log File protocol. See
Pulling Data Using
Log File Protocol
.
b
Schedule SIEM to retrieve the output file from CA ACF2.
If the zOS platform is configured to serve files through FTP, SFTP, or allow SCP,
then no interim FTP server is required and SIEM can pull the output file directly
from the mainframe. The following text must be commented out using //* or
deleted from the
QexACF2_jcl.txt
file:
//FTP EXEC PGM=FTP,REGION=3800K
//INPUT DD *
<IPADDR>
<USER>
<PASSWORD>
PUT '<ACFOUT>' EARL_<THEIPOFTHEMAINFRAMEDEVICE>/<ACFOUT>
QUIT
//OUTPUT DD SYSOUT=*
//SYSPRINT DD SYSOUT=*
You are now ready to configure the Log File protocol. See
Pulling Data Using
Log File Protocol
.
Pulling Data Using
Log File Protocol
A log file protocol source allows SIEM to retrieve archived log files from a remote
host. The CA ACF2 DSM supports the bulk loading of log files using the log file
protocol source.
When configuring your CA ACF2 DSM to use the log file protocol, make sure the
hostname or IP address configured in the CA ACF2 is the same as configured in
the Remote Host parameter in the Log File protocol configuration.
Summary of Contents for Security Information and Event Manager
Page 2: ......
Page 8: ......
Page 20: ......
Page 22: ......
Page 24: ......
Page 26: ......
Page 32: ......
Page 34: ......
Page 36: ......
Page 38: ......
Page 44: ......
Page 58: ......
Page 90: ......
Page 92: ......
Page 94: ......
Page 114: ......
Page 116: ......
Page 122: ......
Page 124: ......
Page 126: ...Configuring DSMs 110 FIREEYE...
Page 128: ......
Page 130: ......
Page 132: ......
Page 136: ......
Page 140: ......
Page 144: ......
Page 172: ......
Page 176: ...Configuring DSMs 160 ISC BIND...
Page 180: ......
Page 182: ......
Page 184: ......
Page 204: ......
Page 224: ......
Page 246: ......
Page 250: ......
Page 256: ......
Page 260: ......
Page 276: ......
Page 282: ......
Page 284: ......
Page 306: ......
Page 308: ......
Page 318: ......
Page 322: ......
Page 324: ......
Page 346: ......
Page 356: ......
Page 366: ......
Page 384: ......
Page 392: ......
Page 394: ......
Page 396: ......
Page 398: ......
Page 404: ......
Page 426: ......