Configuring DSMs
186
J
UNIPER
N
ETWORKS
If you select the option
Send Syslog from vGW management server
, all
events forwarded to SIEM contain the IP address of the vGW management
server.
•
Send Syslog from Firewalls
- Distribute logging with each Firewall Security
VM providing syslog events.
Step 5
Type values for the following parameters:
a
Syslog Server
- Type the IP address of your vGW management server if you
selected to
Send Syslog from vGW management server
. Or, type the IP
address of SIEM if you selected
Send Syslog from Firewalls
.
b
Syslog Server Port
- Type the port address for syslog. This is typically port
514.
Step 6
From the
External Logging
panel, click
Save
.
Only changes made to the
External Logging
section are stored when you click
Save
. Any changes made to NetFlow require that you save using the button within
NetFlow Configuration
section.
Step 7
From the
NetFlow Configuration
panel, select the
enable
check box.
NetFlow does not support central logging from a vGW management server. From
the External Logging section, you must select the option
Send Syslog from
Firewalls
.
Step 8
Type values for the following parameters:
a
NetFlow collector address
- Type the IP address of SIEM.
b
NetFlow collector port
- Type a port address for NetFlow events.
NOTE
SIEM typically uses port 2055 for NetFlow event data on Behavioral Flow
Collectors. You must configure a different NetFlow collector port on your Juniper
Networks vGW Series Virtual Gateway for NetFlow.
Step 9
From the
NetFlow Configuration
, click
Save
.
Step 10
You are now ready to configure the log source in SIEM.
SIEM automatically detects syslog forwarded from Juniper Networks vGW. If you
want to manually configure SIEM to receive syslog events:
From the
Log Source Type
drop-down list box, select
Juniper vGW
.
For more information on configuring log sources, see the
Log Sources User Guide
.
For more information, see your Juniper Networks vGW documentation.
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......