Configuring DSMs
134
IBM
SIEM to read iSecurity events using the Log Enhanced Event Protocol (LEEF).
Before configuring your device in SIEM, you must:
1
Configure the Raz-Lee iSecurity user interface to forward syslog events to SIEM.
For more information, see
Configuring iSecurity to Forward Syslog Events
.
2
Configure the log source in SIEM. For more information, see
Configuring a Log
Source in SIEM
.
Configuring iSecurity to Forward Syslog Events
To integrate the device with SIEM:
Step 1
Log in to the IBM System i command line interface.
Step 2
Type the following command to access the audit menu options:
STRAUD
Step 3
From the Audit menu, select
81. System Configuration
.
The iSecurity/Base System Configuration window is displayed.
Step 4
From the iSecurity/Base System Configuration menu, select
31. SYSLOG
Definitions
.
The SYSLOG Definitions window is displayed.
Step 5
Configure the following parameters:
a
Send SYSLOG message
- Select
Yes
.
b
Destination address
- Type the IP address of SIEM.
c
“Facility” to use
- Type a facility level.
d
“Severity” range to auto send
- Type a severity level.
e
Message structure
- Type any additional message structure parameters
required for your syslog messages.
Step 6
You are now ready to configure the log source in SIEM.
Configuring a Log Source in SIEM
You are now ready to configure the log source in SIEM. SIEM automatically
detects syslog events from iSecurity on the System i. If you want to manually
configure SIEM to receive events from a System i device:
From the
Log Source Type
drop-down list box, select the
IBM iSecurity
option.
For more information on configuring log sources, see the
Log Sources User Guide
.
For more information about Raz-Lee iSecurity, see your vendor documentation.
IBM Lotus Domino
You can integrate an IBM Lotus Domino device with SIEM. An IBM Lotus Domino
device accepts events using SNMP. Before you configure SIEM to integrate with
an IBM Lotus Domino device, you must:
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......