Configuring DSMs
McAfee Web Gateway
203
NOTE
Selecting a value for the Credibility parameter greater than 5 will weight your
McAfee Application / Change Control log source with a higher importance
compared to other log sources in SIEM.
Step 9
Click
Save
.
Step 10
On the
Admin
tab, click
Deploy Changes
.
For more information on configuring log sources, see the
Log Sources User Guide
.
McAfee Web
Gateway
You can configure McAfee Web Gateway to integrate with SIEM using one of the
following methods:
•
Configuring McAfee Web Gateway for Syslog
•
Configuring McAfee Web Gateway for the Log File Protocol
NOTE
McAfee Web Gateway is formerly known as McAfee WebWasher.
Configuring McAfee
Web Gateway for
Syslog
To integrated McAfee Web Gateway with SIEM:
Step 1
Log in to your McAfee Web Gateway console.
Step 2
Using the toolbar, click
Configuration
.
Step 3
Click the
File Editor
tab.
Step 4
Expand the appliance files and select the file
/etc/rsyslog.conf.
The file editor displays the rsyslog.conf file for editing.
Step 5
Modify the rsyslog.conf file to include the following information:
# send access log to siem
*.info;daemon.!=info;mail.none;authpriv.none;cron.none
-/var/log/messages
*.info;mail.none;authpriv.none;cron.none @<IP Address>:<Port>
Where:
<IP Address>
is the IP address of SIEM.
<Port>
is the syslog port number, for example 514.
Step 6
Click
Save Changes
.
You are now ready to import a policy for the syslog handler on your McAfee Web
Gateway appliance. For more information, see
Importing the Syslog Log Handler
.
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......