Configuring DSMs
256
N
ORTEL
N
ETWORKS
Configure the Log Source within SIEM
You are now ready to configure the log source in SIEM.
Step 1
To configure SIEM to receive events from a Nortel Switched Firewall 5100 device
using OPSEC, you must select the
Nortel Switched Firewall 5100
option from the
Log Source Type
drop-down list box.
Step 2
To configure SIEM to receive events from a Check Point SmartCenter Server using
OPSEC LEA, you must select the
LEA
option from the
Protocol Configuration
drop-down list box when configuring your protocol configuration.
For more information, see the
Log Sources User Guide
.
Nortel Switched
Firewall 6000
A SIEM Nortel Switched Firewall 6000 DSM accepts events using either syslog or
OPSEC. SIEM records all relevant events. Before configuring a Nortel Switched
Firewall device in SIEM, you must configure your device to send events to SIEM.
This section provides information on configuring a Nortel Switched Firewall 6000
device with SIEM using one of the following methods:
•
Integrating Nortel Switched Firewall Using Syslog
•
Integrating Nortel Switched Firewall Using OPSEC
Integrating Nortel
Switched Firewall
Using Syslog
This method ensures the SIEM Nortel Switched Firewall 6000 DSM accepts events
using syslog. Before you configure SIEM to integrate with a Nortel Switched
Firewall 6000 DSM, you must:
Step 1
Log into your Nortel Switched Firewall device command line interface (CLI).
Step 2
Type the following command:
/cfg/sys/log/syslog/add
Step 3
Type the IP address of your SIEM system at the following prompt:
Enter IP address of syslog server:
A prompt is displayed to configure the severity level.
Step 4
Configure
info
as the desired severity level. For example:
Enter minimum logging severity
(emerg | alert | crit | err | warning | notice | info | debug):
info
A prompt is displayed to configure the facility.
Step 5
Configure
auto
as the local facility. For example:
Enter the local facility (auto | local0-local7): auto
Step 6
Apply the configuration:
apply
Step 7
You are now ready to configure the log source in SIEM.
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......