Configuring DSMs
386
W
EBSENSE
V-S
ERIES
nohup /bin/bash –c “while [ 1 ] ; do tail -F
/opt/WCG/logs/leef.log | nc <IP Address> 514; sleep 1; done” &
NOTE
You may need to type the logging command in
Step 3
or copy the command to a
text editor to interpret the quotation marks.
You are now ready to configure the log source in SIEM.
SIEM automatically detects LEEF formatted syslog events from the Websense
V-Series Content Gateway. However, to manually configure SIEM to receive
events from a Websense V-Series appliance:
From the
Log Source Type
drop-down list box, select the
Websense V
Series
option. For more information on configuring log sources, see the
Log
Sources User Guide
.
For more information on configuring your Websense V-Series appliance, consult
your vendor documentation.
Configuring Log File
Protocol for the
Websense V-Series
Content Gateway
The log file protocol allows SIEM to retrieve archived log files from a remote host.
The Websense V-Series DSM supports the bulk loading of log files using the log
file protocol to provide events on a scheduled interval. To configure your
Websense V-Series Content Gateway:
1 Configure event logging in the Management Console, see
Configuring the
Management Console
.
2 Pull data using the log file protocol source. For more information, see
Pulling Data
Using Log File Protocol
.
Configuring the Management Console
To configure event logging in the Content Management Console:
Step 1
Log into your Websense Content Gateway interface.
Step 1
Click the
Configure
tab.
Step 2
Select
Subsystems > Logging
.
The General Logging Configuration window is displayed.
Step 3
Select
Log Transactions and Errors
.
Step 4
Select
Log Directory
to specify the directory path of the stored event log files.
The directory you define must already exist and the Websense user must have
read and write permissions for the specified directory. The default directory is
/opt/WGC/logs
Step 5
Click
Apply
.
Step 6
Click the
Formats
tab.
Step 7
Select
Netscape Extended Format
as your format type.
Step 8
Click
Apply
.
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......