Configuring DSMs
IBM AS/400 iSeries
131
Step 4
Type the path to the
Remote Directory
.
This is the default directory path storing your IBM AIX log files.
Step 5
Type the
FTP File Pattern
.
The FTP File Pattern parameter must use a regular expression that matches the
log files of your IBM AIX server.
Step 6
Select the
Event Generator
as
LINEBYLINE
.
For more information on configuring the Log File protocol, see the
Log Sources
User Guide
.
IBM AS/400 iSeries
SIEM has three options for integrating to an IBM AS/400 (or IBM OS/400) iSeries
using one of the following software products:
•
Integrating an IBM AS/400 iSeries DSM
- The IBM AS/400 iSeries DSM uses
the DSPJRN command to write audit journal records to a database file that is
pushed to an FTP server for retrieval by SIEM using the Log File protocol
source.
For more information, see
Integrating an IBM AS/400 iSeries DSM
.
For more information on configuring log sources and protocols, see
Pulling
Data Using Log File Protocol
.
•
LogAgent for System i
- Accepts all Common Event Format (CEF) formatted
syslog messages. You can integrate an IBM OS/400 device and above using
the LogAgent for System i software. Once you have your LogAgent for System i
software configured, use the Log File protocol source to pull the syslog CEF
messages.
For more information, see your Patrick Townsend Security Solutions LogAgent
for System i documentation.
For more information on configuring log sources and protocols, see
Pulling
Data Using Log File Protocol
.
•
PowerTech Interact
- Accepts all Common Event Format (CEF) formatted
syslog messages. You can integrate an IBM OS/400 device using the
PowerTech Interact software. Once you have configured your Power Interact
software, use the Log File protocol source to pull the syslog CEF messages.
For more information, see your PowerTech Interact documentation.
•
Raz-Lee iSecurity
- Accepts iSecurity formatted events using the Log
Enhanced Event Protocol (LEEF). Once you have configured your iSecurity
software, then SIEM detects the syslog messages. For more information, see
Configuring Raz-Lee iSecurity
.
Integrating an IBM
AS/400 iSeries DSM
The SIEM IBM AS/400 iSeries DSM allows you to integrate with an IBM AS/400
iSeries to collect audit records and event information. The IBM AS/400 iSeries
DSM uses an agent running on the iSeries that manages, gathers and transfers
the event information. The program leverages the DSPJRN command to write
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......