Configuring DSMs
52
P
ALO
A
LTO
N
ETWORKS
The SIEM Palo Alto PA Series DSM accepts events using syslog. SIEM records
syslog threat events forwarded from Palo Alto PA Series firewalls that have been
classified into critical, high, medium, low and informational event categories.
Before you configure SIEM to integrate with a Palo Alto PA Series firewall, you
must:
Step 1
Log in to the Palo Alto Networks user interface.
Step 2
Click the
Device
tab.
The Device options menu is displayed.
Step 3
Select
Log Destinations > Syslog
.
The log settings configuration menu is displayed.
Step 4
Click
New
.
The New Syslog Setting menu is displayed.
Step 5
Configure the following options in the New Syslog Setting page:
•
Name
- Type the name of the syslog server.
•
Server
- Type the IP address of your SIEM system.
•
Port
- Type the port number the SIEM system to receive syslog events. The
default port number is 514.
•
Facility
- From the drop-down list box, select the facility level from the available
options.
Step 6
Click
OK
.
You have now entered the syslog destination, but you must also define the severity
of events that are contained in the syslog messages.
Step 7
Select
Log Setting > System
.
The System Log Settings window is displayed, which allow you to define the
contents of the syslog messages for SIEM.
Step 8
Click
Edit
.
Step 9
Select the check box for each event severity level you want contained in the syslog
message.
Step 10
Type the name of the syslog destination you created in
Step 5
.
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......