Configuring DSMs
McAfee Web Gateway
205
This will give you the access handler file required to configure your McAfee Web
Gateway appliance.
access_log_file_loghandler.xml
Step 3
Log in to your McAfee Web Gateway console.
Step 4
Using the menu toolbar, click
Policy
.
NOTE
If there is an existing access log configuration in your McAfee Web Gateway
appliance, you must delete the existing access log from the Rule Set Library
before adding access_log_file_loghandler.xml.
Step 5
Click
Log Handler
.
Step 6
Using the menu tree, select
Default
.
Step 7
From the
Add
drop-down list box, select
Rule Set from Library
.
The Add a Rule Set from Library window is displayed.
Step 8
Click
Import from File button
.
Step 9
Navigate to the directory containing the access_log_file_loghandler.xml file you
downloaded in
Step 1
, and select syslog_loghandler.xml as the file to import.
When importing the rule set for access_log_file_loghandler.xml, a conflict occurs
stating the Access Log Configuration already exists in the current configuration
and a conflict solution is presented.
Step 10
If the McAfee Web Gateway appliance detects that the Access Log Configuration
already exists, select the
Conflict Solution: Change name
option presented to
resolve the rule set conflict.
For more information on resolving conflicts, see your McAfee Web Gateway
vendor documentation.
You must configure your access.log file to be pushed to an interim server on an
auto rotation. It does not matter if you push your files to the interim server based on
time or size for your access.log file. For more information on auto rotation, see
your McAfee Web Gateway vendor documentation.
NOTE
Due to the size of access.log files generated, we recommend you select the
option
GZIP files after rotation
in your McAfee Web Gate appliance.
Step 11
Click
OK
.
Step 12
Click
Save Changes
.
NOTE
By default McAfee Web Gateway is configured to write access logs to the
/opt/mwg/log/user-defined-logs/access.log/ directory.
You are now ready to configure SIEM to receive access.log files from McAfee Web
Gateway. For more information, see
Pulling Data Using the Log File Protocol
.
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......