QRadar コンソールでのMEGイベントのマッピング
MEG イベントを QRadar® QID マップの等価なものにマッピングすることで、MEG イベントは QRadar によって分類され、処理される。
手順
- QRadar コンソールからログのアクティビティを確認し、ログソースフィルタを追加します。イベントはログ・アクティビティに表示されます。
- イベントを開き、 [Log Activity] タブで[ Map Event] をクリックします。
- イベントをマップする QID を入力します。QIDには以下のイベント・マッピングを使用する。
イベント ログ・ソース・タイプ カテゴリー QID MaaS360® MEGパスワード認証成功 IBM® MaaS360 モバイル・エンタープライズ・ゲートウェイ MEG_AUTH 1002750002 MaaS360 MEG Password Authentication Failure IBM MaaS360 Mobile Enterprise Gateway MEG_AUTH 1002750003 MaaS360 MEG Certificate Authentication Success IBM MaaS360 Mobile Enterprise Gateway MEG_AUTH 1002750007 MaaS360 MEG Certificate Authentication Failure IBM MaaS360 Mobile Enterprise Gateway MEG_AUTH 1002750008 MaaS360 MEG Resource Authentication Success IBM MaaS360 Mobile Enterprise Gateway MEG_AUTH 1002750006 MaaS360 MEG Resource Authentication Failure IBM MaaS360 Mobile Enterprise Gateway MEG_AUTH 1002750004 新しいログ・アクティビティが表示されます。 - ステップ1から3を繰り返して、追加のログイベントをマッピングする。