Configuring DSMs
64
C
ISCO
•
Log Name
- Type a log name.
•
File Name
- Use the default configuration value.
•
Maximum File Size
- Use the default configuration value.
•
Log Level
- Select
Information
(Default).
•
Retrieval Method
- Select
Syslog Push
.
•
Hostname
- Type the IP address or server name of your SIEM system.
•
Protocol
- Select
UDP
.
•
Facility
- Use the default configuration value. This value depends on the
configured Log Type.
Step 5
Save the subscription.
Step 6
You are now ready to configure the log source in SIEM.
To configure SIEM to receive events from a Cisco IronPort device:
From the
Log Source Type
drop-down list box, select the
Cisco IronPort
option.
For more information on configuring devices, see the
Log Sources User Guide
.
For more information about your server, see your vendor documentation.
IronPort Web Content
Filter
A SIEM Cisco IronPort DSM retrieves web content filtering events in W3C format
from a remote source using the log file protocol. Your system must be running the
latest version of log file protocol to integrate with a Cisco IronPort device. To
configure your Cisco IronPort device to push web content filter events, you must
configure a log subscription for the web content filter using the W3C format. For
more information on configuring a log subscription, see your Cisco IronPort
documentation.
You are now ready to configure the log source and protocol SIEM.
Step 1
From the
Log Source Type
drop-down list box, select
Cisco IronPort
.
Step 2
From the
Protocol Configuration
drop-down list box, select
Log File
protocol
option.
Step 3
Select
W3C
as the
Event Generator
used to process the web content filter log
files.
Step 4
The
FTP File Pattern
parameter must use a regular expression that matches the
log files generated by the web content filter logs.
For more information on configuring devices, see the
Log Sources User Guide
.
Cisco NAC
A SIEM Cisco NAC DSM accepts events using syslog. SIEM records all relevant
audit, error, and failure events as well as quarantine and infected system events.
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......