Configuring DSMs
316
S
OPHOS
•
Sophos PureMessage for Linux
- Stores events in a PostgreSQL database
specified as pmx_quarantine.
This section provides information on the following:
•
Integrating SIEM with Sophos PureMessage for Microsoft Exchange
•
Integrating SIEM with Sophos PureMessage for Linux
Integrating SIEM with
Sophos
PureMessage for
Microsoft Exchange
To integrate SIEM with Sophos PureMessage for Microsoft Exchange:
Step 1
Log in to the Microsoft SQL Server command line interface (CLI):
osql -E -S localhost\sophos
Step 2
Type which database you want to integrate with SIEM:
use savexquar;
go
Step 3
Type the following command to create a SIEM view in your Sophos database to
support SIEM:
create view siem_view as select 'Windows PureMessage' as
application, id, reason, timecreated, emailonly as sender,
filesize, subject, messageid, filename from dbo.quaritems,
dbo.quaraddresses where ItemID = ID and Field = 76;
Go
Once you have created your SIEM view, you must configure SIEM to receive event
information using the JDBC protocol.
To configure the Sophos PureMessage DSM with SIEM, see
Configure SIEM to
Receive Events From Sophos PureMessage for Microsoft Exchange
.
Configure SIEM to Receive Events From Sophos PureMessage for Microsoft
Exchange
To configure SIEM to access the Sophos PureMessage for Microsoft Exchange
database using the JDBC protocol:
Step 1
Log in to SIEM.
Step 2
Click the
Admin
tab.
Step 3
In the navigation menu, click
Data Sources
.
The Data Sources panel is displayed.
Step 4
Click the
Log Sources
icon.
The Log Sources window is displayed.
Step 5
Click
Add
.
The Add a log source window is displayed.
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......