Configuring DSMs
200
M
C
A
FEE
Configuring the Log Source in SIEM
You are now ready to configure the log source and protocol in SIEM:
Step 1
To configure SIEM to receive events from a McAfee ePO device, you must select
the
McAfee ePolicy Orchestrator
option from the
Log Source Type
drop-down
list box.
Step 2
To configure SNMP, you must select the same SNMP version configured on your
McAfee ePO device. From the
Protocol Configuration
drop-down list box, select
the
SNMPv2
, or
SNMPv3
option.
Step 3
If you are using SNMPv2 or SNMPv3, you must select the
Include OIDs in Event
Payload
check box.
For more information on configuring SNMP on your ePO device, see the McAfee
website at http://www.mcafee.com.
McAfee Application
/ Change Control
A SIEM McAfee Application / Change Control DSM accepts change control events
using Java Database Connectivity (JDBC). SIEM records all relevant McAfee
Application / Change Control events. This document includes information on
configuring SIEM to access the database containing events using the JDBC
protocol.
To configure SIEM:
Step 1
Log in to SIEM.
Step 2
Click the
Admin
tab.
Step 3
In the navigation menu, click
Data Sources
.
The Data Sources panel is displayed.
Step 4
Click the
Log Sources
icon.
The Log Sources window is displayed.
Step 5
Click
Add
.
The Add a log source window is displayed.
Step 6
Using the
Log Source Type
drop-down list box, select
McAfee Application /
Change Control
.
Step 7
Using the
Protocol Configuration
drop-down list box, select
JDBC
.
You must refer to the Configure Database Settings on your ePO Management
Console to configure the McAfee Application / Change Control DSM in SIEM.
Step 8
Configure the following values:
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......