Configuring DSMs
Examples
237
In addition to the parameters listed above, you can add any NVP parameters to
your log. The additional parameters are added to the payload, however, these
values are not parsed.
Step 10
You are now ready to configure the log source in SIEM.
To configure SIEM to receive events from an NVP DSM:
From the
Log Source Type
drop-down list box, select the
Name Value Pair
option.
For more information on configuring log sources, see the
Log Sources User Guide
.
Examples
Example 1
The following example parses all fields:
DeviceType=NVP EventName=Test
DestinationIpPostNAT=172.16.45.10 DeviceTime=2007/12/14
09:53:49 SourcePort=1111 Identity=FALSE SourcePortPostNAT=3333
DestinationPortPostNAT=6666 HostName=testhost
DestinationIpPreNAT=172.16.10.10 SourcePortPreNAT=2222
DestinationPortPreNAT=5555 SourceMAC=AA:15:C5:BF:C4:9D
SourceIp=172.16.200.10 SourceIpPostNAT=172.16.40.50
NetBIOSName=testbois DestinationMAC=00:41:C5:BF:C4:9D
EventCategory=Accept DestinationPort=4444
GroupName=testgroup SourceIpPreNAT=172.16.70.87UserName=root
DestinationIp=172.16.30.30
Example 2
The following example provides identity using the destination IP address:
<133>Apr 16 12:41:00 172.16.10.10 namevaluepair:
DeviceType=NVP EventName=Test EventCategory=Accept
Identity=TRUE SourceMAC=AA:15:C5:BF:C4:9D
Identity
Type TRUE or FALSE to indicate whether you wish this
event to generate an identity event. An identity event is
generated if the log message contains the SourceIp (if the
IdentityUseSrcIp parameter is set to TRUE) or
DestinationIp (if the IdentityUseSrcIp parameter is set to
FALSE) and one of the following parameters: UserName,
SourceMAC, HostName, NetBIOSName, or GroupName.
IdentityUseSrcIp
Type TRUE or FALSE (default). TRUE indicates that you
wish to use the source IP address for identity. FALSE
indicates that you wish to use the destination IP address
for identity. This parameter is used only if the Identity
parameter is set to TRUE.
Table 44-1
NVP Log Format Tags (continued)
Tag
Description
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......