Configuring DSMs
384
W
EBSENSE
V-S
ERIES
To configure SIEM to receive events from a Websense V-Series appliance:
From the
Log Source Type
drop-down list box, select
Websense V Series
.
For more information on configuring log sources, see the
Log Sources User Guide
.
For more information on configuring your Websense V-Series appliance, consult
your vendor documentation.
Websense V-Series
Content Gateway
The SIEM Websense V-Series Content Gateway DSM supports event for web
content on Websense V-Series appliances with the Content Gateway software.
The SIEM Websense V-Series Content Gateway DSM accepts events using
syslog to stream events or using the log file protocol to provide events to SIEM.
Before you can integrate SIEM, you must select one of the following configuration
methods:
•
To configure syslog for your Websense V-Series, see
Configuring Syslog for the
Websense V-Series Content Gateway
.
•
To configure the log file protocol for your Websense V-Series, see
Configuring
Log File Protocol for the Websense V-Series Content Gateway
.
Configuring Syslog
for the Websense
V-Series Content
Gateway
The Websense V-Series DSM supports Websense V-Series appliances running
the Websense Content Gateway on Linux software installations. Before
configuring SIEM, you must configure the Websense Content Gateway to provide
LEEF formatted syslog events.
To configure your Websense V-Series Content Gateway:
1 Configure the Management Console. For more information, see
Configuring the
Management Console
.
2 Enable event logging. For more information, see
Enabling Event Logging
.
Configuring the Management Console
To configure event logging in the Content Gateway Manager:
Step 1
Log into your Websense Content Gateway Manager.
Step 1
Click the
Configure
tab.
Step 2
Select
Subsystems > Logging
.
The General Logging Configuration window is displayed.
Step 3
Select
Log Transactions and Errors
.
Step 4
Select
Log Directory
to specify the directory path of the stored event log files.
The directory you define must already exist and the Websense user must have
read and write permissions for the specified directory. The default directory is
/opt/WGC/logs
Step 5
Click
Apply
.
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......