Configuring DSMs
150
IBM
NOTE
If the JVM Logs changes affect the cell, you must restart all of the WebSphere
Application Servers in the cell before you continue.
You are now ready to import the file into SIEM using the Log File Protocol, see
Pulling Data Using Log File Protocol
.
Pulling Data Using
Log File Protocol
A log file protocol source allows SIEM to retrieve archived log files from a remote
host. The IBM WebSphere Application Server DSM supports the bulk loading of
log files using the log file protocol source.
When configuring your IBM WebSphere device to use the log file protocol, make
sure the hostname or IP address configured in the IBM WebSphere device is the
same as configured in the Remote Host parameter in the Log File Protocol
configuration. For more information, see the
Log Sources User Guide
.
You are now ready to configure the log source and protocol in SIEM:
Step 1
To configure SIEM to receive events from an IBM WebSphere Application Server,
you must select the
IBM WebSphere Application Server
option from the
Log
Source Type
drop-down list box.
Step 2
To configure the log file protocol, you must select the
Log File
option from the
Protocol Configuration
drop-down list box. Your system must be running the
latest version of log file protocol to integrate with the IBM WebSphere Application
Server:
Step 3
The remote directory must point to the cell and file path you specified in
Step 5
.
Step 4
Configure the FTP File Pattern by typing
.+\.log
based on the example
specified in
Step 4
and configure the
Event Generator
as
WebSphere
Application Server
.
Step 5
We recommend that you use a secure protocol for transferring files, such as
Secure File Transfer Protocol (SFTP).
NOTE
We recommend when scheduling a Log File protocol, you select a recurrence
time for the log file protocol shorter than the scheduled write interval of the
WebSphere Application Server log files. This ensures that WebSphere events are
collected by the Log File Protocol before a the new log file overwrites the old
event log.
For information about installing and configuring the log file protocol, see the
Log
Sources User Guide
.
For more information about IBM WebServer Application Server, see your vendor
documentation.
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......