Configuring DSMs
86
E
NTERASYS
You are now ready to configure the log source SNMP protocol in SIEM. See
Configuring SIEM
.
For information on configuring SNMP in SIEM, see the
Log Sources User Guide
.
Creating a Policy
with a Syslog
Notification Rule
This procedure describes how to configure an Alarm Tool policy using a Syslog
notification rule in the Log Event Extended Format (LEEF) message format. LEEF
is the preferred message format for sending notifications to Dragon Network
Defense when the notification rate is very high or when IPv6 addresses are
displayed.
If you prefer not to use syslog notifications in LEEF format, refer to your
Enterasys
IPS documentation
for more information.
NOTE
Use SNMPv3 notification rules if you need to transfer PDATA, which is a binary
data element. Do not use a Syslog notification rule.
To configure Enterasys Dragon with an Alarm Tool policy using a syslog notification
rule:
Step 1
Log in to the Enterasys Dragon EMS.
Step 2
Click the
Alarm Tool
icon.
Step 3
Configure the Alarm Tool Policy:
a
In the
Alarm Tool Policy View > Custom Policies
menu tree, right-click and
select
Add Alarm Tool Policy
.
The Add Alarm Tool Policy window is displayed.
b
In the
Add Alarm Tool Policy
field, type a policy name.
For example:
Enterasys Networks
c
Click
OK
.
d
In the menu tree, select Enterasys Networks.
Step 4
To configure the event group:
a
Click the
Events Group
tab.
b
Click
New
.
The Event Group Editor is displayed.
c
Select the event group or individual events to monitor.
d
Click
Add
.
A prompt is displayed.
e
Click
Yes
.
f
In the right column of the Event Group Editor, type
Dragon-Events
.
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......