Symantec 엔드포인트 보호
IBM QRadar DSM for Symantec Endpoint Protection은 Symantec Endpoint Protection 시스템에서 이벤트를 수집합니다.
IBM® QRadar® DSM for Symantec Endpoint Protection은 Symantec Endpoint Protection System의 이벤트를 영어, 프랑스어, 독일어, 이탈리아어, 일본어, 러시아어 및 폴란드어 언어로 구문 분석합니다.
다음 표에서는 Symantec Endpoint Protection DSM의 스펙에 대해 설명합니다.
| 스펙 | 값 |
|---|---|
| 제조업체 | Symantec |
| DSM 이름 | Symantec 엔드포인트 보호 |
| RPM 파일 이름 | DSM-SymantecEndpointProtection-QRadar_version-build_number.noarch.rpm |
| 지원되는 버전 | 엔드포인트 보호 V11, V12및 V14 |
| 프로토콜 | Syslog |
| 이벤트 형식 | Syslog |
| 기록되는 이벤트 유형 | 모든 감사 및 보안 로그 |
| 자동 감지 여부 | 예 |
| ID 포함 여부 | 아니오 |
| 사용자 정의 특성 포함 여부 | 아니오 |
| 자세한 정보 | Symantec웹 사이트 (https://www.symantec.com) |
Symantec Endpoint Protection을 QRadar 와 통합하려면 다음 단계를 완료하십시오.
- 자동 업데이트가 활성화되어 있지 않은 경우 IBM® 지원 웹사이트에서 다음 RPM의 최신 버전을 다운로드하여 QRadar
Console에 설치합니다:
- DSMCommon RPM
- Symantec 엔드포인트 보호 DSM RPM
- syslog 이벤트를 QRadar에 전송하도록 Symantec Endpoint Protection 디바이스를 구성하십시오.
- QRadar 가 자동으로 로그 소스를 발견하지 못하는 경우 QRadar Console에 Symantec Endpoint Protection 로그 소스를 추가하십시오.
- QRadar 가 올바르게 구성되었는지 확인하십시오.다음 표에는 Symantec Endpoint Protection의 정규화된 이벤트 메시지 샘플이 표시되어 있습니다.
표 2. Symantec Endpoint Protection 샘플 메시지 이벤트 이름 하위 레벨 카테고리 샘플 로그 메시지 차단됨 액세스가 거부됨 <51>Mar 3 13:52:13 <Server> Syman tecServer: USER,<IP_address>, Blocked,[AC13-1.5] Block from load ing other DLLs - Caller MD5=xxxxxx xxxxxxxxxxxxxxxxxxxxxxxxx,Load Dl l,Begin: 2017-03-03 13:48:18,End: 2 017-03-03 13:48:18,Rule: Corp Endpo int - Browser Restrictions | [AC13- 1.5] Block from loading other DLLs, 6804,C:/Program Files (x86)/Microso ft Office/Office14/WINPROJ.EXE,0,N o Module Name,C:/Users/USER /AppData/Local/assembly/dl3/DMD7K 4QX.8GW/WQ9LV1W4.8HL/e705c114/00 6fef9d_f364d101/ProjectPublisher 2010.DLL,User: USER,Domain : LAB,Action Type: ,File size ( bytes): 4216832,Device ID: SCSI\ Disk&Ven_ATA&Prod_SAMSUNG_SSD_ PM83\4&27c82505&0&000000