Configuring DSMs
358
S
YMANTEC
Step 10
On the
Admin
tab, click
Deploy Changes
.
SIEMFor information on configuring the JDBC protocol, see the
Log Sources User
Guide.
Symantec Data
Loss Prevention
(DLP)
A SIEM Symantec Data Loss Protection (DLP) DSM accepts events from a
Symantec DLP appliance using syslog. Before configuring SIEM, you must
configure response rules on your Symantec DLP. The response rule allows the
Symantec DLP appliance to forward syslog events to SIEM when a data loss policy
violation occurs. Integrating Symantec DLP requires you to create two protocol
response rules (SMTP and None of SMTP) for SIEM. These protocol response
rules create an action to forward the event information, using syslog, when an
incident is triggered.
To configure Symantec DLP with SIEM, you must:
1 Create an SMTP response rule. For more information, see
Creating an SMTP
Response Rule
.
2 Create a None of SMTP response rule. For more information, see
Creating a None
Of SMTP Response Rule
.
3 Configure SIEM. For more information, see
Configuring SIEM with Symantec DLP
.
Creating an SMTP
Response Rule
To configure an SMTP response rule in Symantec DLP:
Step 1
Log in to your Symantec DLP user interface.
Step 2
From the menu, select the
Manage > Policies > Response Rules
.
Step 3
Click
Add Response Rule
.
The New Response Rule panel is displayed.
Step 4
Select one of the following response rule types:
•
Automated Response
- Automated response rules are triggered automatically
as incidents occur. This is the default value.
•
Smart Response
- Smart response rules are added to the Incident Command
screen and handled by an authorized Symantec DLP user.
Step 5
Click
Next
.
The Configure Response Rule panel is displayed.
Step 6
Configure the following values:
a
Rule Name
- Type a name for the rule you are creating. This name should be
descriptive enough for policy authors to identify the rule. For example,
SIEM
Syslog SMTP
.
b
Description
- Optional. Type a description for the rule you are creating.
Step 7
Click
Add Condition
.
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......