Configuring DSMs
65
S
TONESOFT
M
ANAGEMENT
C
ENTER
The SIEM Stonesoft Management Center DSM accepts events using syslog. SIEM
records all relevant LEEF formatted syslog events. Before configuring SIEM, you
must configure your Stonesoft Management Center to export LEEF formatted
syslog events.
This document includes the steps required to edit LogServerConfiguration.txt file.
Configuring the text file allows Stonesoft Management Center to export event data
in LEEF format using syslog to SIEM. For detailed configuration instructions, see
the
StoneGate Management Center Administrator’s Guide
.
The following steps are required to integrate Stonesoft Management Center with
SIEM:
1
Configuring the Log Server
2
Configuring a Traffic Rule for Syslog
3
Configuring the Log Source in SIEM
Configuring the Log
Server
To configure Stonesoft Management Center, perform the following steps:
Step 1
Log in to the appliance hosting your Stonesoft Management Center.
Step 2
Stop the Stonesoft Management Center Log Server:
•
Windows
- Select one of the following methods to stop the Log Server:
-
Stop the Log Server in the Windows Services list.
-
Run the batch file
<installation path>/bin/sgStopLogSrv.bat
.
•
Linux
- To stop the Log Server in Linux, run the script
<installation
path>/bin/sgStopLogSrv.sh
.
Step 3
Edit the LogServerConfiguration.txt file. The configuration file is located in the
following directory:
<installation path>/data/LogServerConfiguration.txt
Step 4
Configure the following parameters in the LogServerConfiguration.txt file:
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......