You are now ready to configure the log source in SIEM.
SIEM automatically detects syslog events from your EMC VMWare server.
However, if you want to manually configure SIEM to receive events from your
VMWare ESX server:
From the
Log Source Type
drop-down list box, select
EMC VMWare
.
Configuring the
VMWare Protocol
When configuring the EMC VMWare DSM to use the VMWare protocol, we
recommend you create a user who is a member of the root group for SIEM, but
provide the user with an assigned role of read-only permissions. This ensures that
the VMWare virtual environment collects events using the VMWare protocol and
maintains a level of security for the new SIEM user you are adding.
To integrate EMC VMWare with SIEM, you must:
1 Create an ESX account for SIEM. For more information, see
Creating an ESX
Account for SIEM
.
2 Configure account permissions for the SIEM user. For more information, see
Configuring Account Permissions
.
3 Configure the VMWare protocol in SIEM. For more information, see
Configuring
SIEM
.
CAUTION
Creating a user who is not part of the root or an administrative group may lead to
some events not being collected by SIEM. We recommend adding your SIEM
user to an administrative group, but assign a read-only role.
Creating an ESX
Account for SIEM
To create a SIEM user account for EMC VMWare:
Step 1
Log in to your ESX host using the vSphere Client.
Step 2
Click the
Local Users & Groups
tab.
Step 3
Click
Users
.
A list of user accounts is displayed.
Step 4
Right-click and select
Add
.
The Add New User window is displayed.
Step 5
Configure the following parameters:
a
Login
- Type a login name for the new user.
b
UID
- Optional. Type a user ID.
c
User Name
- Optional. Type a user name for the account.
d
Password
- Type a password for the account.
e
Confirm Password
- Type the password again as confirmation.
f
Group
- From the
Group
drop-down list box, select
root
.
Summary of Contents for Security Information and Event Manager
Page 2: ......
Page 8: ......
Page 20: ......
Page 22: ......
Page 24: ......
Page 26: ......
Page 32: ......
Page 34: ......
Page 36: ......
Page 38: ......
Page 44: ......
Page 58: ......
Page 90: ......
Page 92: ......
Page 94: ......
Page 114: ......
Page 116: ......
Page 122: ......
Page 124: ......
Page 126: ...Configuring DSMs 110 FIREEYE...
Page 128: ......
Page 130: ......
Page 132: ......
Page 136: ......
Page 140: ......
Page 144: ......
Page 172: ......
Page 176: ...Configuring DSMs 160 ISC BIND...
Page 180: ......
Page 182: ......
Page 184: ......
Page 204: ......
Page 224: ......
Page 246: ......
Page 250: ......
Page 256: ......
Page 260: ......
Page 276: ......
Page 282: ......
Page 284: ......
Page 306: ......
Page 308: ......
Page 318: ......
Page 322: ......
Page 324: ......
Page 346: ......
Page 356: ......
Page 366: ......
Page 384: ......
Page 392: ......
Page 394: ......
Page 396: ......
Page 398: ......
Page 404: ......
Page 426: ......