Configuring DSMs
75
U
NIVERSAL
DSM
SIEM collects and correlates events from network infrastructure and security
devices. Once the events are collected and before the correlation can begin, the
individual events from these devices must be properly parsed to determine the
event name, IP addresses, protocol, and ports. For common network devices
(such as, NetScreen Firewalls) predefined DSMs have been engineered into SIEM
to properly parse all event messages from the respective devices. Once the events
from a device have been parsed by the DSM, SIEM can continue to correlate
events into offenses.
If an enterprise network has one or more network or security devices that are not
officially supported (no specific DSM for the device exists), you can use the
Universal DSM. The Universal DSM allows you to forward events and messages
from unsupported devices to SIEM for correlation. SIEM integrates with many
common protocol sources using the Universal DSM.
For more information about log source protocols, see the
Log Sources User Guide
.
To configure the Universal DSM, you must use device extensions to associate a
Universal DSM to devices. Before you define device extension information using
the log sources window in the Admin tab, you must create an extensions document
for the log source. For information about device extensions, see the
Log Sources
User Guide
.
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......