Um H3C Comware Platform-Ereignisse zu erfassen, aktivieren Sie syslog-Einstellungen und konfigurieren Sie einen Protokollhost. H3C Switches, H3C Router, H3C Wireless LAN Devices und H3C IP Security Devices werden von QRadarunterstützt.
Vorgehensweise
- Melden Sie sich über den Konsolenport oder über Telnet oder SSH an der Befehlszeilenschnittstelle an.
Weitere Informationen zu Anmeldemethoden finden Sie im Abschnitt Anmeldung bei der Befehlszeilenschnittstelle im Konfigurationshandbuch für Ihre H3C -Geräte.
- Geben Sie den Befehl <system_name>
system-view ein, um auf die Systemansicht zuzugreifen.
- Geben Sie zum Aktivieren der syslog-Einstellungen die folgenden Befehle in der aufgelisteten Reihenfolge ein.
- info-center source default loghost deny
- info-center source AAA loghost level informational
- info-center source ACL loghost level informational
- info-center source FIPS loghost level informational
- info-center source HTTPD loghost level informational
- info-center source IKE loghost level informational
- info-center source IPSEC loghost level informational
- info-center source LOGIN loghost level informational
- info-center source LS loghost level informational
- info-center source PKI loghost level informational
- info-center source PORTSEC loghost level informational
- info-center source PWDCTL loghost level informational
- info-center source RADIUS loghost level informational
- info-center source SHELL loghost level informational
- info-center source SNMP loghost level informational
- info-center source SSHS loghost level informational
- info-center source TACACS loghost level informational
- info-center loghost <QRadar Event Collector IP>
514
- Geben Sie den Befehl quit
<system_name> ein, um die Systemansicht zu beenden.