Configuring DSMs
24
B
LUE
C
OAT
SG
Step 4
Type a format name for the custom format.
Step 5
Select
Custom format string
.
Step 6
Type the following custom format for SIEM:
Bluecoat|src=$(c-ip)|srcport=$(c-port)|dst=$(cs-uri-address)|ds
tport=$(cs-uri-port)|username=$(cs-username)|devicetime=$(gmtti
me)|s-action=$(s-action)|sc-status=$(sc-status)|cs-method=$(cs-
method)|time-taken=$(time-taken)|sc-bytes=$(sc-bytes)|cs-bytes=
$(sc-bytes)|cs-uri-scheme=$(cs-uri-scheme)|cs-host=$(cs-host)|c
s-uri-path=$(cs-uri-path)|cs-uri-query=$(cs-uri-query)|cs-uri-e
xtension=$(cs-uri-extension)|cs-auth-group=$(cs-auth-group)|s-h
ierarchy=$(s-hierarchy)|rs(Content-Type)=$(rs(Content-Type))|cs
(User-Agent)=$(cs(User-Agent))|cs(Referer)=$(cs(Referer))|sc-fi
lter-result=$(sc-filter-result)|filter-category=$(sc-filter-cat
egory)|cs-uri=$(cs-uri)
Step 7
Select
Log Last Header
from the drop-down list box.
Step 8
Click
OK
.
Step 9
Click
Apply
.
NOTE
The custom format for SIEM supports additional key-value pairs using the Blue
Coat ELFF format. For more information, see
Custom Format Addition Key-Value
Pairs
.
You are ready to enable access logging on your Blue Coat device. For more
information, see
Creating a Log Facility
Creating a Log
Facility
To use the custom log format created for SIEM, you must associate the custom log
format for SIEM to a facility. To create a log facility:
Step 1
Select
Configuration > Access Logging > Logs
.
The Logs Configuration window is displayed.
Step 2
Click
New
.
The Create Log window is displayed.
Step 3
Configure the following parameters:
•
Log Name
- Type a name for the log facility.
•
Log Format
- Select the custom format you created in
Step 4
.
•
Description
- Type a description for the log facility.
Step 4
Click
OK
.
Step 5
Click
Apply
.
You are ready to enable logging on the Blue Coat device. For more information,
see
Enabling Access Logging
.
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......