Configuring DSMs
Cisco ASA
57
Step 6
Add the following Logged Attributes:
•
Message-Type
•
User-Name
•
Nas-IP-Address
•
Authen-Failure-Code
•
Caller-ID
•
NAS-Port
•
Author-Data
•
Group-Name
•
Filter Information
•
Logged Remotely
Step 7
Configure a time frame for Cisco ACS to generate a new csv file.
Step 8
Click
Submit
.
Step 9
You are now ready to configure the log source in SIEM.
You can integrate your Cisco ACS with SIEM using the SIEM Adaptive Log
Exporter. The Adaptive Log Exporter reads the csv files in the Cisco ACS root log
directory and forwards the events to SIEM using syslog. For more information on
using the Adaptive Log Exporter, see the
Adaptive Log Exporter Users Guide
.
If you are not using the Adaptive Log Exporter, SIEM automatically detects the
Cisco ACS events from the Adaptive Log Exporter. However, if you want to
manually configure SIEM to receive events from Cisco ACS:
From the
Log Source Type
drop-down list box, select the
Cisco ACS
option.
For more information on configuring log sources, see the
Log Sources User
Guide
.
For more information about Cisco ACS, see your vendor documentation.
Cisco ASA
You can integrate a Cisco Adaptive Security Appliance (ASA) with SIEM. A Cisco
ASA DSM accepts events using syslog or NetFlow using NetFlow Security Event
Logging (NSEL). SIEM records all relevant events. Before you configure SIEM,
you must configure your Cisco ASA device to forward syslog or NetFlow NSEL
events to SIEM.
Choose one of the following options:
•
Forward events to SIEM using syslog. See
Integrating Cisco ASA Using Syslog
•
Forward events to SIEM using NetFlow NSEL. See
Integrating Cisco ASA for
NetFlow using NSEL
Summary of Contents for Security Information and Event Manager
Page 2: ......
Page 8: ......
Page 20: ......
Page 22: ......
Page 24: ......
Page 26: ......
Page 32: ......
Page 34: ......
Page 36: ......
Page 38: ......
Page 44: ......
Page 58: ......
Page 90: ......
Page 92: ......
Page 94: ......
Page 114: ......
Page 116: ......
Page 122: ......
Page 124: ......
Page 126: ...Configuring DSMs 110 FIREEYE...
Page 128: ......
Page 130: ......
Page 132: ......
Page 136: ......
Page 140: ......
Page 144: ......
Page 172: ......
Page 176: ...Configuring DSMs 160 ISC BIND...
Page 180: ......
Page 182: ......
Page 184: ......
Page 204: ......
Page 224: ......
Page 246: ......
Page 250: ......
Page 256: ......
Page 260: ......
Page 276: ......
Page 282: ......
Page 284: ......
Page 306: ......
Page 308: ......
Page 318: ......
Page 322: ......
Page 324: ......
Page 346: ......
Page 356: ......
Page 366: ......
Page 384: ......
Page 392: ......
Page 394: ......
Page 396: ......
Page 398: ......
Page 404: ......
Page 426: ......