Configuring DSMs
50
O
PEN
S
OURCE
SNORT
A SIEM Open Source SNORT DSM accepts SNORT events using syslog. SIEM
records all relevant SNORT events. SourceFire’s VRT certified rules for registered
SNORT users are supported, however, Bleeding Edge, Emerging Threat, and
other third-party rule sets may not be fully supported by the Open Source SNORT
DSM.
NOTE
The below procedure applies to a system operating Red Hat Enterprise. The
procedures below may vary for other operating systems.
Before you configure SIEM to integrate with a SNORT device, you must:
Step 1
Configure SNORT on a remote system.
Step 2
Open the
snort.conf
file.
Step 3
Uncomment the following line:
output alert_syslog:LOG_AUTH LOG_INFO
Step 4
Save and exit the file.
Step 5
Open the following file:
/etc/init.d/snortd
Step 6
Add an
-s
to the following lines, as shown in the example below:
daemon /usr/sbin/snort $ALERTMODE $BINARY_LOG $NO PACKET_LOG
$DUMP_APP -D $PRINT_INTERFACE -i $i -s -u $USER -g $GROUP $CONF
-i $LOGIR/$i $PASS_FIRST
daemon /usr/sbin/snort $ALERTMODE $BINARY_LOG $NO_PACKET_LOG
$DUMP_APP -D $PRINT_INTERFACE $INTERFACE -s -u $USER -g $GROUP
$CONF -i $LOGDIR
Step 7
Save and exit the file.
Step 8
Restart SNORT:
/etc/init.d/snortd restart
Step 9
Open the
syslog.conf
file.
Step 10
Update the file to reflect the following:
auth.info
@<IP Address>
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......