Configuring DSMs
220
M
ICROSOFT
Configuring
Microsoft IIS Using
the Adaptive Log
Exporter
The Adaptive Log Exporter is a stand-alone application that allows you to integrate
device logs or application event data with SIEM. The Adaptive Log Export supports
NCSA, IIS, and W3C active log formats.
To integrate the Adaptive Log Exporter with Microsoft IIS, perform the following
steps:
Step 1
Log in to your Microsoft Information Services (IIS) Manager.
Step 2
In the IIS Manager menu tree, expand
Local Computer
.
Step 3
Select
Web Sites
.
Step 4
Right-click on
Default Web Site
and select
Properties
.
The Web Sites Properties window is displayed.
Step 5
From the
Active Log Format
drop-down list box, select one of the following:
•
Select
NCSA
. Go to
Step 9
.
•
Select
IIS
. Go to
Step 9
.
•
Select
W3C
. Go to
Step 6
.
Step 6
Click
Properties
.
The Properties window is displayed.
Step 7
Click the
Advanced
tab.
Step 8
From the list of properties, select all event properties that you want to apply to the
Microsoft IIS event log. The selected properties must include the following:
a
Select the
Method (cs-method)
check box.
b
Select the
Protocol Version (cs-version)
check box.
Step 9
Click
OK
.
Step 10
You are now ready to configure the Adaptive Log Exporter.
For more information on installing and configuring Microsoft IIS for the Adaptive
Log Exporter, see the
Adaptive Log Exporter User Guide
.
Microsoft ISA
A SIEM Microsoft Internet and Acceleration (ISA) DSM accepts events using
syslog. You can integrate Microsoft ISA Server with SIEM using the Adaptive Log
Exporter. For more information on the Adaptive Log Exporter, see the
Adaptive
Log Exporter Users Guide
.
You are now ready to configure the log source in SIEM.
To configure SIEM to receive events from a Microsoft ISA Server:
From the
Log Source Type
drop-down list box, select the
Microsoft ISA
option.
For more information on configuring devices, see the
Log Sources User Guide
.
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......