SSH CryptoAuditor
Das IBM QRadar DSM für SSH CryptoAuditor erfasst Protokolle von einem SSH- CryptoAuditor.
Die folgende Tabelle enthält die Spezifikationen für das SSH-DSM CryptoAuditor .
| Spezifikation | Wert |
|---|---|
| Hersteller | SSH-Kommunikationssicherheit |
| Produkt | CryptoAuditor |
| DSM-Name | SSH CryptoAuditor |
| RPM-Dateiname | DSM-SSHCryptoAuditor-QRadar_release-Build_number.noarch.rpm |
| Unterstützte Versionen | 1.4.0 oder höher |
| Ereignisformat | Syslog |
| Aufgezeichnete QRadar -Ereignistypen | Prüfung, Forensik |
| Protokollquellentyp in der QRadar -Benutzerschnittstelle | SSH CryptoAuditor |
| Automatisch erkannt? | Ja |
| Enthält Identität? | Nein |
| Angepasste Eigenschaften einschließen? | Nein |
| Weitere Informationen | Website zur SSH-Kommunikationssicherheit (http://www.ssh.com/) |
Führen Sie die folgenden Schritte aus, um Ereignisse von SSH CryptoAuditor an QRadarzu senden:
- Wenn automatische Updates nicht aktiviert sind, laden Sie die neueste Version der folgenden RPMs von der IBM® Support Website herunter und installieren Sie sie auf Ihrer QRadar Konsole:
- DSMCommon-RPM
- SSH-RPM CryptoAuditor
- Für jede Instanz von SSH CryptoAuditor, konfigurieren Sie Ihr SSH CryptoAuditor System, um mit QRadar zu kommunizieren.
- Wenn QRadar SSH CryptoAuditor, nicht automatisch entdeckt wird, erstellen Sie eine Protokollquelle auf der QRadar Konsole für jede Instanz von SSH CryptoAuditor. Verwenden Sie die folgenden SSH-Parameter für CryptoAuditor :
Parameter Wert Protokollquellentyp SSH CryptoAuditor Protokollkonfiguration Syslog