Configuring DSMs
44
N
AME
V
ALUE
P
AIR
The Name Value Pair (NVP) DSM allows you to integrate SIEM with devices that
may not natively send logs using syslog. The NVP DSM provides a log format that
allows you to send logs to SIEM. For example, for a device that does not export
logs natively with syslog, you can create a script to export the logs from a device
that SIEM does not support, format the logs in the NVP log format, and send the
logs to SIEM using syslog. The NVP DSM log source configured in SIEM then
receives the logs and is able to parse the data since the logs are received in the
NVP log format.
NOTE
The NVP DSM is not automatically detected by SIEM.
The NVP DSM accepts events using syslog. SIEM records all relevant events. The
log format for the NVP DSM must be a tab-separated single line list of
Name=Parameter. The NVP DSM does not require a valid syslog header.
NOTE
The NVP DSM assumes an ability to create custom scripts or thorough knowledge
of your device capabilities to send logs to SIEM using syslog in NVP format.
This section provides information on the following:
•
NVP Log Format
•
Examples
NVP Log Format
Table 44-1
includes a list of tags that the NVP DSM is able to parse:
Table 44-1
NVP Log Format Tags
Tag
Description
DeviceType
Type
NVP
as the DeviceType. This identifies the log
formats as a Name Value Pair log message.
This is a required parameter and
DeviceType=NVP
must
be the first pair in the list.
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......