Configuring DSMs
Cisco IOS
65
Before configuring a Cisco NAC device in SIEM, you must configure your device to
send syslog events to SIEM.
To configure the device to send syslog events to SIEM:
Step 1
Log in to the Cisco NAC user interface.
Step 2
In the Monitoring section, select
Event Logs
.
Step 3
Click the
Syslog Settings
tab.
Step 4
In the
Syslog Server Address
field, type the IP address of your SIEM system.
Step 5
In the
Syslog Server Port
field, type the syslog port. The default is 512.
Step 6
In the
System Health Log Interval
field, type the frequency, in minutes, for
system statistic log events.
Step 7
Click
Update
.
Step 8
You are now ready to configure the log source in SIEM.
To configure SIEM to receive events from a Cisco NAC device:
From the
Log Source Type
drop-down list box, select
Cisco NAC Appliance
.
For more information on configuring log sources, see the
Log Sources User
Guide
.
Cisco IOS
You can integrate Cisco IOS series devices with SIEM. A Cisco IOS DSM accepts
Cisco IOS events using syslog. SIEM records all relevant events.
NOTE
Make sure all Access Control Lists (ACLs) are set to LOG.
Before you configure SIEM to integrate with a Cisco IOS server, you must:
Step 1
Type the following command to log in to the router in privileged-exec.
enable
Step 2
Type the following command to switch to configuration mode:
conf t
Step 3
Type the following commands:
logging <IP address>
logging source-interface <interface>
Where:
<
IP address>
is the IP address hosting SIEM and the SIM components.
<interface>
is the name of the interface, for example, dmz, lan, ethernet0, or
ethernet1.
Step 4
Type the following to configure the priority level:
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......