Para recopilar sucesos de H3C Comware Platform, habilite los valores de syslog y configure un host de registro. H3C Switches, H3C Routers, H3C Wireless LAN Devices y H3C IP Security Devices están soportados por QRadar.
Procedimiento
- Inicie sesión en la interfaz de la línea de mandatos utilizando el puerto de la consola, o utilizando Telnet o SSH.
Para obtener más información sobre los métodos de inicio de sesión, consulte la sección Inicio de sesión en la CLI en la guía de configuración para los dispositivos H3C .
- Para acceder a la vista del sistema, escriba el mandato <system_name>
system-view .
- Para habilitar los valores de syslog, escriba los mandatos siguientes en el orden en que aparecen listados.
- info-center source default loghost deny
- info-center source AAA loghost level informational
- info-center source ACL loghost level informational
- info-center source FIPS loghost level informational
- info-center source HTTPD loghost level informational
- info-center source IKE loghost level informational
- info-center source IPSEC loghost level informational
- info-center source LOGIN loghost level informational
- info-center source LS loghost level informational
- info-center source PKI loghost level informational
- info-center source PORTSEC loghost level informational
- info-center source PWDCTL loghost level informational
- info-center source RADIUS loghost level informational
- info-center source SHELL loghost level informational
- info-center source SNMP loghost level informational
- info-center source SSHS loghost level informational
- info-center source TACACS loghost level informational
- info-center loghost <QRadar Event Collector IP>
514
- Para salir de la vista del sistema, escriba el mandato quit
<system_name> .