Configuring DSMs
296
RSA A
UTHENTICATION
M
ANAGER
Where
<IP address>
is the IP address or hostname of SIEM.
Step 4
Save the
ims.properties
files.
Step 5
Open the following file for editing:
/etc/syslog.conf
Step 6
Type the following command to add SIEM as a syslog entry:
*.* @<IP address>
Where
<IP address>
is the IP address or hostname of SIEM.
Step 7
Type the following command to restart the syslog services for Linux.
service syslog restart
Step 8
You are now ready to configure the log sources and protocol in SIEM:
To configure SIEM to receive events from your RSA Authentication Manager:
From the
Log Source Type
drop-down list box, select the
RSA
Authentication Manager
option.
For more information, see the
Log Sources User Guide.
For more information on configuring syslog forwarding, see your RSA
Authentication Manager documentation.
Configuring Syslog on RSA Authentication Manager for Windows
To configure RSA Authentication Manager for syslog using Microsoft Windows:
Step 1
Log in to the system hosting your RSA Security Console.
Step 2
Open the following file for editing based on your operating system:
/Program Files/RSASecurity/RSAAuthenticationManager/utils/
resources/ims.properties
Step 3
Add the following enteries to the
ims.properties
file:
ims.logging.audit.admin.syslog_host = <IP address>
ims.logging.audit.admin.use_os_logger = true
ims.logging.audit.runtime.syslog_host = <IP address>
ims.logging.audit.runtime.use_os_logger = true
ims.logging.system.syslog_host = <IP address>
ims.logging.system.use_os_logger = true
Where
<IP address>
is the IP address or hostname of SIEM.
Step 4
Save the
ims.properties
files.
Step 5
Restart RSA services.
Step 6
You are now ready to configure the log source in SIEM.
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......