Professional Documents
Culture Documents
You are here: Content Update > Event Sources > Linux > Linux
https://siem-as1:8443/help/Subsystems/eventsourceupdate/content/devices/html/rhlinu... 17/03/2015
Linux Página 2 de 8
Linux
RSA enVision Event Source
Last Modified: Saturday, December 6, 2014
Event Source (Device) Product Information
Vendor ed t, ove , e n
Event Source (Device) Linux
Supported Versions Red Hat Enterprise Linux 3.x, 4.x, 5.x, 6.0, 7.0
Novell SuSE Linux Enterprise 9, 10, 10.2, 11
Debian GNU/Linux 3.1, 4.0
Additional Downloads nicwtmp.sh
RSA Product Information
Supported Version RSA enVision 4.1
Security Analytics 10.0 and later
Event Source (Device) Type rhlinux, 27
Collection Method Syslog
Event Source (Device) Class.Subclass Host.UNIX
Content 2.0 Table Unix
This document contains the following information for the Linux event source:
l on ur t on nstruct ons
l e e se otes
l e e se otes
l e e se otes
l e e se otes
l e e se otes
l e e se otes
l e e se otes
Configure Linux
Follow the appropriate configuration instructions for your Linux vendor:
l ove SuSE nu on ur t on nstruct ons
l t er nu on ur t on nstruct ons
fI you use Red Hat Linux, you must also perform the following tasks:
1. on ure ud td on ed t nu .
2. on ure M o s or ed t nu .
3. on ure t e t es Serv ce.
https://siem-as1:8443/help/Subsystems/eventsourceupdate/content/devices/html/rhlinu... 17/03/2015
Linux Página 3 de 8
Configure DP
To configure SuSE Linux using DP
1. On the Linux appliance, log on as root.
2. Open the etc s s o n s s o n con n file.
3. At the end of the file, add the following lines:
destination loghost {
udp("xxx.xxx.xxx.xxx" port(yy));
};
log {
source(src);
destination(loghost);
};
where:
¡ xxx.xxx.xxx.xxx is the IP address of the RSA enVision appliance.
¡ yy is the port number on which the enVision appliance is listening for incoming syslog
messages.
/etc/init.d/syslog restart
ote If you have Novell SuSE 9 or earlier, you must stop
and start the service by running these commands:
/etc/init.d/syslog stop
/etc/init.d/syslog start
Configure TCP
You must complete the following tasks to configure Novell SuSE through TCP:
I. Configure the RSA enVision appliance to accept syslog in TCP packets
I. Configure SuSE Linux to send syslog in TCP packets
Configure the RSA enVision appliance to Accept Syslog in TCP Pac ets
https://siem-as1:8443/help/Subsystems/eventsourceupdate/content/devices/html/rhlinu... 17/03/2015
Linux Página 4 de 8
3. On the Manage Collector Service window, click the name of your site or node.
4. Click the arrow at the end of the n or t on line.
5. In the sten ort field, enter the port number on which the enVision appliance listens for
TCP packets.
6. Click dd.
7. Enter the IP address of your SuSE event source.
8. Click .
9. Click .
destination loghost {
};
log {
source(src);
destination(loghost);
};
where:
¡ xxx.xxx.xxx.xxx is the IP address of the enVision appliance .
¡ yy is the port number on which the enVision appliance is listening for incoming syslog
messages.
/etc/init.d/syslog start
https://siem-as1:8443/help/Subsystems/eventsourceupdate/content/devices/html/rhlinu... 17/03/2015
Linux Página 5 de 8
.de ug xxx.xxx.xxx.xxx
https://siem-as1:8443/help/Subsystems/eventsourceupdate/content/devices/html/rhlinu... 17/03/2015
#daemon prog " E S"
¡
illproc prog
# illproc prog
$Home !!!! !
ipta les-save