Configuring DSMs
Juniper JunOS
179
Configuring Juniper
Networks NSM in
SIEM
To configure SIEM to integrate with a Juniper Networks NSM device:
Step 1
From the
Log Source Type
drop-down list box, select
Juniper Networks
Network and Security Manager
.
Step 2
From the
Protocol Configuration
drop-down list box, select
Juniper NSM
.
Step 3
Configure the following values for the Juniper NSM protocol:
NOTE
In the SIEM interface, the Juniper NSM protocol configuration enables you to use
the Juniper Networks NSM IP address by selecting the Use NSM Address for
Event Source check box. If you wish to change the configuration to use the
originating IP address (clear the check box), you must log in to your SIEM
Console, as a root user, and reboot the Console (for an all-in-one system) or the
Event Collector hosting the log sources (in a distributed environment) using the
following command:
shutdown -r now
Juniper JunOS
A SIEM Juniper JunOS Platform DSM accepts events using syslog,
structured-data syslog, or PCAP (SRX-Series only). SIEM records all valid syslog
or structured-data syslog events.
The SIEM Juniper JunOS Platform DSM supports the following Juniper devices
running JunOS:
•
Juniper M-Series Multiservice Edge Routing
•
Juniper MX-Series Ethernet Services Router
•
Juniper T-Series Core Platform
•
Juniper SRX-Series Services Gateway
Table 36-6
Juniper NSM Protocol Parameters
Parameter
Description
Log Source Identifier
Type the IP address or hostname for the log source.
The log source identifier must be unique for the log source
type.
IP
Type the IP address or hostname of the Juniper Networks
NSM server.
Inbound Port
Type the inbound port to which the Juniper Networks NSM
sends communications.The valid range is 0 to 65536. The
default is 514.
Redirection Listen
Port
Type the port to which traffic is forwarded. The valid range is
0 to 65,536. The default is 516.
Use NSM Address for
Log Source
Select this check box if you want to use the Juniper NSM
management server’s IP address instead of the log source’s
IP address. By default, the check box is selected.
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......