Configuring DSMs
61
S
OPHOS
This section provides information on the following:
•
Sophos Enterprise Console
•
Sophos PureMessage
•
Sophos Astaro Security Gateway
•
Sophos Web Security Appliance
Sophos Enterprise
Console
SIEM has two options for gathering events from a Sophos Enterprise Console
using JDBC. Select the method that best applies to your Sophos Enterprise
Console installation:
•
Configure SIEM Using the Sophos Enterprise Console Protocol
•
Configure SIEM Using the JDBC Protocol
NOTE
To use the Sophos Enterprise Console protocol, you must ensure that the Sophos
Reporting Interface is installed with your Sophos Enterprise Console. If you do not
have the Sophos Reporting Interface, you must configure SIEM using the JDBC
protocol. For information on installing the Sophos Reporting Interface, see your
Sophos Enterprise Console documentation.
Configure SIEM
Using the Sophos
Enterprise Console
Protocol
A SIEM Sophos Enterprise Console DSM accepts events using Java Database
Connectivity (JDBC). The Sophos Enterprise Console DSM works in coordination
with the Sophos Enterprise Console protocol to combine payload information from
anti-virus, application control, device control, data control, tamper protection, and
firewall logs in the vEventsCommonData table and provide these events to SIEM.
You must install the Sophos Enterprise Console protocol before configuring SIEM.
Configure SIEM to Receive Events
To configure SIEM to access the Sophos database using the JDBC protocol:
Step 1
Log in to SIEM.
Step 2
Click the
Admin
tab.
Step 3
In the navigation menu, click
Data Sources
.
The Data Sources panel is displayed.
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......