SSH CryptoAuditor

Das IBM QRadar DSM für SSH CryptoAuditor erfasst Protokolle von einem SSH- CryptoAuditor.

Die folgende Tabelle enthält die Spezifikationen für das SSH-DSM CryptoAuditor .

Tabelle 1. SSH CryptoAuditor DSM-Spezifikationen
Spezifikation Wert
Hersteller SSH-Kommunikationssicherheit
Produkt CryptoAuditor
DSM-Name SSH CryptoAuditor
RPM-Dateiname DSM-SSHCryptoAuditor-QRadar_release-Build_number.noarch.rpm
Unterstützte Versionen 1.4.0 oder höher
Ereignisformat Syslog
Aufgezeichnete QRadar -Ereignistypen Prüfung, Forensik
Protokollquellentyp in der QRadar -Benutzerschnittstelle SSH CryptoAuditor
Automatisch erkannt? Ja
Enthält Identität? Nein
Angepasste Eigenschaften einschließen? Nein
Weitere Informationen Website zur SSH-Kommunikationssicherheit (http://www.ssh.com/)

Führen Sie die folgenden Schritte aus, um Ereignisse von SSH CryptoAuditor an QRadarzu senden:

  1. Wenn automatische Updates nicht aktiviert sind, laden Sie die neueste Version der folgenden RPMs von der IBM® Support Website herunter und installieren Sie sie auf Ihrer QRadar Konsole:
    • DSMCommon-RPM
    • SSH-RPM CryptoAuditor
  2. Für jede Instanz von SSH CryptoAuditor, konfigurieren Sie Ihr SSH CryptoAuditor System, um mit QRadar zu kommunizieren.
  3. Wenn QRadar SSH CryptoAuditor, nicht automatisch entdeckt wird, erstellen Sie eine Protokollquelle auf der QRadar Konsole für jede Instanz von SSH CryptoAuditor. Verwenden Sie die folgenden SSH-Parameter für CryptoAuditor :
    Parameter Wert
    Protokollquellentyp SSH CryptoAuditor
    Protokollkonfiguration Syslog