Configuring DSMs
12
CA T
ECHNOLOGIES
This section provides information on the following DSMs:
•
CA ACF2
•
CA Top Secret
CA ACF2
The CA Access Control Facility (ACF2) DSM allows you to use an IBM mainframe
to collect events and audit transactions. SIEM retrieves archived log files from a
remote host using the log file protocol and records all relevant information from the
event.
To integrate CA ACF2 events into SIEM:
1
The IBM mainframe records all security events as Service Management
Framework (SMF) records in a live repository.
2
The CA ACF2 data is extracted from the live repository using the SMF dump utility.
The SMF file contains all of the events and fields from the previous day in raw SMF
format.
3
The
QexACF2.load.trs
program pulls data from the SMF formatted file. The
QexACF2.load.trs
program only pulls the relevant events and fields for SIEM
and writes that information in a condensed format for SIEM compatibility. The
information is saved in a location accessible by SIEM.
4
SIEM uses the log file protocol source to retrieve the output file information for
SIEM on a scheduled basis. SIEM then imports and processes this file.
This document includes:
•
Configuring CA Top Secret to Integrate with SIEM
•
Pulling Data Using Log File Protocol
Configuring CA ACF2
to Integrate with
SIEM
To integrate CA ACF2 with SIEM:
Step 1
From the Enterasys Extranet website, download the following compressed file:
qexacf2_bundled.tar.gz
Step 2
On a Linux-based operating system, extract the file:
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......