Configuring DSMs
297
To configure SIEM to receive events from your RSA Authentication Manager:
From the
Log Source Type
drop-down list box, select the
RSA
Authentication Manager
option.
For more information, see the
Log Sources User Guide.
For more information on configuring syslog forwarding, see your RSA
Authentication Manager documentation.
Configuring RSA
Using the Log File
Protocol
The log file protocol allows SIEM to retrieve archived log files from a remote host.
The RSA Authentication Manager DSM supports the bulk loading of log files using
the log file protocol source.
The procedure to configure your RSA Authentication Manager using the log file
protocol depends on the version of RSA Authentication Manager:
•
If you are using RSA Authentication Manager v7.x, see
Configuring RSA
Authentication Manager 7.x
.
•
If you are using RSA Authentication Manager v6.x, see
Configuring RSA
Authentication Manager 6.x
.
Configuring RSA Authentication Manager 7.x
To configure your RSA Authentication Manager v7.x device:
Step 1
Log in to the RSA Security Console.
Step 2
Click
Administration > Log Management > Recurring Log Archive Jobs
.
Step 3
In the Schedule section, configure values for the
Job Starts
,
Frequency
,
Run
Time
, and
Job Expires
parameters.
Step 4
For the
Operations
field, select
Export
Only
or
Export
and
Purge
for the
following settings:
Administration Log Settings
,
Runtime Log Settings
, and
System Log Settings
.
NOTE
The
Export and Purge
operation exports log records from the database to the
archive and then purges the logs form the database. The
Export Only
operation
exports log records from the database to the archive and the records remain in the
database.
Step 5
For
Administration
,
Runtime
, and
System
, configure an Export Directory to
which you want to export your archive files.
We recommend you make sure you can access the Administration Log, Runtime
Log, and System Log using FTP before you continue.
Step 6
For
Administration
,
Runtime
, and
System
parameters, set the
Days Kept
Online
parameter to
1
. Logs older than 1 day are exported. If you selected
Export
and Purge
, the logs are also purged from the database.
Step 7
Click
Save
.
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......