Configuring DSMs
132
IBM
audit journal records to a database file. These records are reformatted and
forwarded to an FTP server where SIEM can retrieve the records using FTP.
To integrate IBM iSeries events into SIEM:
Step 1
The IBM iSeries system records and writes security events in the Audit Journal
and the QHST logs. QHST logs are stored in the Audit Journal as TYPE5
messages. For more information on configuring your AS/400 iSeries DSM, see
Configuring an IBM iSeries to Integrate with SIEM
.
Step 2
During your scheduled audit collection, the
AJLIB/AUDITJRN
command is run by
an iSeries Job Scheduler using DSPJRN to collect, format and write the Audit
Journal records to a database file. The database file containing the audit record
information is transferred from the iSeries to an FTP server.
Step 3
Use the log file protocol source to pull the formatted audit file from the FTP server
on a scheduled basis. For more information on configuring log sources and
protocols, see
Pulling Data Using Log File Protocol
.
Configuring an IBM iSeries to Integrate with SIEM
To integrate an IBM iSeries with SIEM:
Step 1
From the Enterasys Extranet website, download the following files:
AJLIB.SAVF
Step 2
Copy the
AJLIB.SAVF
file onto a computer or terminal that has FTP access to the
the IBM AS/400 iSeries.
Step 3
Create a generic online SAVF file on the iSeries using the command:
CRTSAVF QGPL/SAVF
Step 4
Using FTP on the computer or terminal, replace the iSeries generic
SAVF
with the
AJLIB.SAVF
file downloaded from Enterasys Extranet:
bin
cd qgpl
lcd c:\
put ajlib.savf savf
quit
If you are transferring your SAVF file from another iSeries, the file must be sent
with the required FTP subcommand
mode BINARY
before the GET or PUT
statement.
Step 5
Restore the AJLIB library on the IBM iSeries:
RSTLIB
Step 6
Setup the data collection start date and time for the Audit Journal Library (AJLIB):
AJLIB/SETUP
You are prompted for a username and password. If you execute the Audit Journal
Collector a failure message is sent to QSYSOPR.
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......