Configuring DSMs
55
R
EDBACK
ASE
The SIEM Redback ASE DSM accepts events using syslog. The Redback ASE
device can send log messages to the Redback device console or to a log server
that is integrated with SIEM to generate deployment specific reports. Before
configuring a Redback ASE device in SIEM, you must configure your device to
send syslog events to SIEM.
To configure the device to send syslog events to SIEM:
Step 1
Log in to your Redback ASE device user interface.
Step 2
Start the CLI configuration mode.
Step 3
In global configuration mode, configure the default settings for the security service:
asp security default
Step 4
In ASP security default configuration mode, configure the IP address of the log
server and the optional transport protocol:
log server <IP address> transport udp port 9345
Where
<IP address>
is the IP address of the SIEM system.
Step 5
Configure the IP address that you want to use as the source IP address in the log
messages:
log source <source IP address>
Where
<source IP address>
is the IP address of the loopback interface in
context local.
Step 6
Commit the transaction.
For more information about Redback ASE device configuration, see your vendor
documentation.
For example, if you want to configure:
•
Log source server IP address 10.172.55.55
•
Default transport protocol: UDP
•
Default server port: 514
The source IP address used for log messages is 10.192.22.24. This address must
be an IP address of a loopback interface in context local.
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......