Configuring DSMs
262
N
OVELL
E
D
IRECTORY
log4j.appender.S=org.apache.log4j.net.SyslogAppender
Step 5
To configure the IP address for the syslog destination, remove the comment
marker (#) and edit the following lines:
log4j.appender.S.Host=<IP address>
log4j.appender.S.Port=<Port>
Where,
<IP address>
is the IP address or hostname of SIEM.
<Port>
is the port number for the UDP or TCP protocol. The default port for syslog
communication is port
514
for SIEM or Event Collectors.
Step 6
To configure the syslog protocol, remove the comment marker (#) and type the
protocol (UDP, TCP, or SSL) use in the following line:
log4j.appender.S.Protocol=TCP
The encrypted protocol SSL is not supported by SIEM.
Step 7
To set the severity level for logging events, remove the comment marker (#) from
the following line:
log4j.appender.S.Threshold=INFO
The default value of INFO is the correct severity level for events.
Step 8
To set the facility for logging events, remove the comment marker (#) from the
following line:
log4j.appender.S.Facility=USER
The default value of USER is the correct facility value for events.
Step 9
To set the facility for logging events, remove the comment marker (#) from the
following line:
log4j.appender.R.MaxBackupIndex=10
Step 10
Save the xdas.properties file.
Once you have configured the syslog properties for XDASv2 events, you are ready
to load the XDASv2 modules.
Loading the XDASv2
Module
Before you can configure events in Novell iManager, you must load the changes
you made to the XDASv2 module. To load the XDASv2 module, select your
operating system.
•
To load the XDASv2 in Linux, see
Loading the XDASv2 on a Linux Operating
System
.
•
To load the XDASv2 in Windows, see
Loading the XDASv2 on a Windows
Operating System
.
NOTE
If your Novell eDirectory has Novell Module Authentication Service (NMAS)
installed with NMAS auditing enabled, the changes made to XDASv2 modules are
loaded automatically. If you have NMAS installed, you should configure event
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......