Configuring DSMs
36
CA T
ECHNOLOGIES
You are now ready to configure the log source and log file protocol in SIEM:
To configure SIEM to receive events from the CA ACF2:
Step 1
From the
Log Source Type
drop-down list box, select the
CA ACF2
option.
Step 2
From the
Protocol Configuration
drop-down list box, select the
Log File
protocol
option.
Step 3
Configure the log file protocol options.
For more information on configuring log sources and protocols, see the
Log
Sources User Guide
.
CA Top Secret
The CA Top Secret DSM allows you to integrate with an IBM zOS mainframe to
collect events and audit transactions. SIEM records all relevant and available
information from the event.
To integrate CA Top Secret events into SIEM:
1
The IBM mainframe records all security events as Service Management
Framework (SMF) records in a live repository.
2
At midnight, the CA Top Secret data is extracted from the live repository using the
SMF dump utility. The SMF file contains all of the events and fields from the
previous day in raw SMF format.
3
The
qextopsloadlib
program pulls data from the SMF formatted file. The
qextopsloadlib
program only pulls the relevant events and fields for SIEM and
writes that information in a condensed format for SIEM compatibility. The
information is saved in a location accessible by SIEM.
4
SIEM uses the log file protocol source to retrieve the output file information for
SIEM on a scheduled basis. SIEM then imports and processes this file.
This document includes:
•
Configuring CA Top Secret to Integrate with SIEM
•
Pulling Data Using Log File Protocol
Configuring CA Top
Secret to Integrate
with SIEM
To integrate CA Top Secret with SIEM:
Step 1
From the Enterasys Extranet website, download the following compressed file:
qextops_bundled.tar.gz
Step 2
On a Linux-based operating system, extract the file:
tar -zxvf qextops_bundled.tar.gz
The following files are contained in the archive:
qextops_jcl.txt
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......