You are now ready to configure the log source in SIEM.
SIEM automatically detects syslog events from your EMC VMWare server.
However, if you want to manually configure SIEM to receive events from your
VMWare ESX server:
From the
Log Source Type
drop-down list box, select
EMC VMWare
.
Configuring the
VMWare Protocol
When configuring the EMC VMWare DSM to use the VMWare protocol, we
recommend you create a user who is a member of the root group for SIEM, but
provide the user with an assigned role of read-only permissions. This ensures that
the VMWare virtual environment collects events using the VMWare protocol and
maintains a level of security for the new SIEM user you are adding.
To integrate EMC VMWare with SIEM, you must:
1 Create an ESX account for SIEM. For more information, see
Creating an ESX
Account for SIEM
.
2 Configure account permissions for the SIEM user. For more information, see
Configuring Account Permissions
.
3 Configure the VMWare protocol in SIEM. For more information, see
Configuring
SIEM
.
CAUTION
Creating a user who is not part of the root or an administrative group may lead to
some events not being collected by SIEM. We recommend adding your SIEM
user to an administrative group, but assign a read-only role.
Creating an ESX
Account for SIEM
To create a SIEM user account for EMC VMWare:
Step 1
Log in to your ESX host using the vSphere Client.
Step 2
Click the
Local Users & Groups
tab.
Step 3
Click
Users
.
A list of user accounts is displayed.
Step 4
Right-click and select
Add
.
The Add New User window is displayed.
Step 5
Configure the following parameters:
a
Login
- Type a login name for the new user.
b
UID
- Optional. Type a user ID.
c
User Name
- Optional. Type a user name for the account.
d
Password
- Type a password for the account.
e
Confirm Password
- Type the password again as confirmation.
f
Group
- From the
Group
drop-down list box, select
root
.
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......