Configuring DSMs
33
I
MPERVA
S
ECURE
S
PHERE
The SIEM Imperva SecureSphere DSM accepts events using syslog. SIEM
records all relevant events. Before configuring an Imperva SecureSphere device in
SIEM, you must configure your device to send syslog events to SIEM.
To configure the device to send syslog events to SIEM:
Step 1
Log in to your SecureSphere device user interface using administrative privileges.
Step 2
Click the
Policies
tab.
Step 3
Click the
Action Sets
tab.
Step 4
To generate events for each alert generated by the SecureSphere device:
a
Create a new action set named
q1labs_alerts
.
b
Click the arrow beside System Log to move the action interface to the
Selected
Actions
list.
c
Expand the
System Log
action group.
d
In the
Action Name
field, type
q1labs_syslog_alerts
.
e
Configure the following parameters:
-
Syslog host
- Type the IP address of the SIEM system to which you want to
send events.
-
Syslog log level
- Select
INFO
.
-
Message
- You must type the following message as a pipe separated
continuous string:
DeviceType=ImpervaSecuresphere Alert|an=$!{Alert.alertMetadat
a.alertName}|at=Securesphere Alert|ad=$!{Alert.description}|s
p=$!{Event.sourceInfo.sourcePort}|s=$!{Event.sourceInfo.sourc
eIp}|d=$!{Event.destInfo.serverIp}|dp=$!{Event.destInfo.serve
rPort}|u=$!{Alert.username}|g=$!{Alert.serverGroupName}
f
Select the
Run on Every Event
check box.
g
Click
Save
.
Step 5
To enable the
q1labs_alerts
action created above, you must edit your policies
to use the alerts action.
The below procedure details the steps to configure the action for a firewall policy.
Repeat this procedure for all required policies.
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......