Configuring DSMs
Oracle Audit Vault
279
event can be mapped to a high-level and low-level category (or QID). Using the
Oracle Audit Vault DSM, category mapping can be done by mapping your high or
low category alerts directly to an alert name (ALERT_NAME field) in the payload.
For information about the Events interface, see the SIEM Users Guide.
To configure Oracle Audit Vault DSM with SIEM, see
Configuring SIEM to Receive
Oracle Audit Vault Alerts
.
Configuring SIEM to
Receive Oracle Audit
Vault Alerts
To configure SIEM to access the Oracle Audit Vault database using the JDBC
protocol:
Step 1
Log in to SIEM.
Step 2
Click the
Admin
tab.
Step 3
In the navigation menu, click
Data Sources
.
The Data Sources panel is displayed.
Step 4
Click the
Log Sources
icon.
The Log Sources window is displayed.
Step 5
Click
Add
.
Step 6
Using the
Log Source Type
drop-down list box, select
Oracle Audit Vault
.
Step 7
Using the
Protocol Configuration
drop-down list box, select
JDBC
.
Step 8
Configure the following values:
a
Database Type:
Oracle
b
Database Name: <
Audit Vault Database Name
>
c
Table Name:
avsys.av$alert_store
d
Select List:
*
e
Compare Field:
ALERT_SEQUENCE
f
IP or Hostname: <
Location of Oracle Audit Vault Server
>
g
Port: <
Default Port
>
h
Username: <
Database Access Username having AV_AUDITOR role
>
i
Password: <
Password
>
j
Polling Interval: <
Default Interval
>
NOTE
Verify the AV_AUDITOR password has been entered correctly before saving the
JDBC protocol configuration. Oracle Audit Vault may lock the user account due to
repeated failed login attempts. When the AV_AUDITOR account is locked, data in
the avsys.av$alert_store cannot be accessed. In order to unlock this user
account, it is necessary to first correct the password entry in the protocol
configuration. Then log in to Oracle Audit Vault through the Oracle sqlplus prompt
as the avadmindva user to perform an alter user <AV_AUDITOR USER> account
unlock command.
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......