QRadar コンソールでのMEGイベントのマッピング

MEG イベントを QRadar® QID マップの等価なものにマッピングすることで、MEG イベントは QRadar によって分類され、処理される。

手順

  1. QRadar コンソールからログのアクティビティを確認し、ログソースフィルタを追加します。
    イベントはログ・アクティビティに表示されます。
  2. イベントを開き、 [Log Activity] タブで[ Map Event] をクリックします。
  3. イベントをマップする QID を入力します。
    QIDには以下のイベント・マッピングを使用する。
    イベント ログ・ソース・タイプ カテゴリー QID
    MaaS360® MEGパスワード認証成功 IBM® MaaS360 モバイル・エンタープライズ・ゲートウェイ MEG_AUTH 1002750002
    MaaS360 MEG Password Authentication Failure IBM MaaS360 Mobile Enterprise Gateway MEG_AUTH 1002750003
    MaaS360 MEG Certificate Authentication Success IBM MaaS360 Mobile Enterprise Gateway MEG_AUTH 1002750007
    MaaS360 MEG Certificate Authentication Failure IBM MaaS360 Mobile Enterprise Gateway MEG_AUTH 1002750008
    MaaS360 MEG Resource Authentication Success IBM MaaS360 Mobile Enterprise Gateway MEG_AUTH 1002750006
    MaaS360 MEG Resource Authentication Failure IBM MaaS360 Mobile Enterprise Gateway MEG_AUTH 1002750004
    新しいログ・アクティビティが表示されます。
  4. ステップ1から3を繰り返して、追加のログイベントをマッピングする。