Configuring DSMs
Cisco IOS
65
Before configuring a Cisco NAC device in SIEM, you must configure your device to
send syslog events to SIEM.
To configure the device to send syslog events to SIEM:
Step 1
Log in to the Cisco NAC user interface.
Step 2
In the Monitoring section, select
Event Logs
.
Step 3
Click the
Syslog Settings
tab.
Step 4
In the
Syslog Server Address
field, type the IP address of your SIEM system.
Step 5
In the
Syslog Server Port
field, type the syslog port. The default is 512.
Step 6
In the
System Health Log Interval
field, type the frequency, in minutes, for
system statistic log events.
Step 7
Click
Update
.
Step 8
You are now ready to configure the log source in SIEM.
To configure SIEM to receive events from a Cisco NAC device:
From the
Log Source Type
drop-down list box, select
Cisco NAC Appliance
.
For more information on configuring log sources, see the
Log Sources User
Guide
.
Cisco IOS
You can integrate Cisco IOS series devices with SIEM. A Cisco IOS DSM accepts
Cisco IOS events using syslog. SIEM records all relevant events.
NOTE
Make sure all Access Control Lists (ACLs) are set to LOG.
Before you configure SIEM to integrate with a Cisco IOS server, you must:
Step 1
Type the following command to log in to the router in privileged-exec.
enable
Step 2
Type the following command to switch to configuration mode:
conf t
Step 3
Type the following commands:
logging <IP address>
logging source-interface <interface>
Where:
<
IP address>
is the IP address hosting SIEM and the SIM components.
<interface>
is the name of the interface, for example, dmz, lan, ethernet0, or
ethernet1.
Step 4
Type the following to configure the priority level:
Summary of Contents for Security Information and Event Manager
Page 2: ......
Page 8: ......
Page 20: ......
Page 22: ......
Page 24: ......
Page 26: ......
Page 32: ......
Page 34: ......
Page 36: ......
Page 38: ......
Page 44: ......
Page 58: ......
Page 90: ......
Page 92: ......
Page 94: ......
Page 114: ......
Page 116: ......
Page 122: ......
Page 124: ......
Page 126: ...Configuring DSMs 110 FIREEYE...
Page 128: ......
Page 130: ......
Page 132: ......
Page 136: ......
Page 140: ......
Page 144: ......
Page 172: ......
Page 176: ...Configuring DSMs 160 ISC BIND...
Page 180: ......
Page 182: ......
Page 184: ......
Page 204: ......
Page 224: ......
Page 246: ......
Page 250: ......
Page 256: ......
Page 260: ......
Page 276: ......
Page 282: ......
Page 284: ......
Page 306: ......
Page 308: ......
Page 318: ......
Page 322: ......
Page 324: ......
Page 346: ......
Page 356: ......
Page 366: ......
Page 384: ......
Page 392: ......
Page 394: ......
Page 396: ......
Page 398: ......
Page 404: ......
Page 426: ......