Configuring DSMs
170
J
UNIPER
N
ETWORKS
Where
<IP address>
is the IP address of the Event Collector you want to
connect to the database.
Step 4
Reload the Postgres service:
su - nsm -c "pg_ctl reload -D /var/netscreen/DevSvr/pgsql/data"
Step 5
As the Juniper Networks NSM user, create the view:
create view strm_avt_view as SELECT a.name, a.category,
v.srcip,v.dstip,v.dstport, v."last", u.name as userinfo, v.id,
v.device, v.vlan,v.sessionid, v.bytecnt,v.pktcnt, v."first" FROM
avt_part v JOIN app a ON v.app =a.id JOIN userinfo u ON
v.userinfo = u.id;
The view is created.
Step 6
You are now ready to configure the log source in SIEM.
To configure SIEM to receive events from a Juniper Networks AVT device:
Step 1
From the
Log Source Type
drop-down list box, select
Juniper Networks AVT
.
Step 2
You must also configure the JDBC protocol for the log source. Use the following
parameters to configure the JDBC protocol:
a
Database Type
- From the
Database Type
drop-down list box, select
Postgres
.
b
Database Name
- Type
profilerDb
.
c
IP or Hostname
- Type the IP address of the Juniper Networks NSM system.
d
Port
- Type
5432
.
e
Username
- Type the username for the profilerDb database.
f
Password
- Type the password for profilerDB database.
g
Table Name
- Type
strm_avt_view
.
h
Select List
- Type
*
for the select list.
i
Compare Field
- Type
id
for the Compare Field.
j
Use Prepared Statements
-The
Use Prepared Statements
check box must be
clear. The Juniper Networks AVT DSM does not support prepared statements.
k
Polling Interval
- Type
10
for the Polling interval.
NOTE
The Database Name and Table Name parameters are case sensitive.
For more information on configuring log sources and protocols, see the
Log
Sources User Guide
.
For more information about the Juniper Networks AVT device, see your vendor
documentation.
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......