Symantec 엔드포인트 보호

IBM QRadar DSM for Symantec Endpoint Protection은 Symantec Endpoint Protection 시스템에서 이벤트를 수집합니다.

IBM® QRadar® DSM for Symantec Endpoint Protection은 Symantec Endpoint Protection System의 이벤트를 영어, 프랑스어, 독일어, 이탈리아어, 일본어, 러시아어 및 폴란드어 언어로 구문 분석합니다.

다음 표에서는 Symantec Endpoint Protection DSM의 스펙에 대해 설명합니다.
표 1. Symantec Endpoint Protection DSM 스펙
스펙
제조업체 Symantec
DSM 이름 Symantec 엔드포인트 보호
RPM 파일 이름 DSM-SymantecEndpointProtection-QRadar_version-build_number.noarch.rpm
지원되는 버전 엔드포인트 보호 V11, V12및 V14
프로토콜 Syslog
이벤트 형식 Syslog
기록되는 이벤트 유형 모든 감사 및 보안 로그
자동 감지 여부
ID 포함 여부 아니오
사용자 정의 특성 포함 여부 아니오
자세한 정보 Symantec웹 사이트 (https://www.symantec.com)
Symantec Endpoint Protection을 QRadar 와 통합하려면 다음 단계를 완료하십시오.
  1. 자동 업데이트가 활성화되어 있지 않은 경우 IBM® 지원 웹사이트에서 다음 RPM의 최신 버전을 다운로드하여 QRadar Console에 설치합니다:
    • DSMCommon RPM
    • Symantec 엔드포인트 보호 DSM RPM
  2. syslog 이벤트를 QRadar에 전송하도록 Symantec Endpoint Protection 디바이스를 구성하십시오.
  3. QRadar 가 자동으로 로그 소스를 발견하지 못하는 경우 QRadar Console에 Symantec Endpoint Protection 로그 소스를 추가하십시오.
  4. QRadar 가 올바르게 구성되었는지 확인하십시오.
    다음 표에는 Symantec Endpoint Protection의 정규화된 이벤트 메시지 샘플이 표시되어 있습니다.
    표 2. Symantec Endpoint Protection 샘플 메시지
    이벤트 이름 하위 레벨 카테고리 샘플 로그 메시지
    차단됨 액세스가 거부됨
     <51>Mar  3 13:52:13 <Server> Syman
    tecServer: USER,<IP_address>,
    Blocked,[AC13-1.5] Block from load
    ing other DLLs - Caller MD5=xxxxxx
    xxxxxxxxxxxxxxxxxxxxxxxxx,Load Dl
    l,Begin: 2017-03-03 13:48:18,End: 2
    017-03-03 13:48:18,Rule: Corp Endpo
    int - Browser Restrictions | [AC13-
    1.5] Block from loading other DLLs,
    6804,C:/Program Files (x86)/Microso
    ft Office/Office14/WINPROJ.EXE,0,N
    o Module Name,C:/Users/USER
    /AppData/Local/assembly/dl3/DMD7K
    4QX.8GW/WQ9LV1W4.8HL/e705c114/00
    6fef9d_f364d101/ProjectPublisher
    2010.DLL,User: USER,Domain
    : LAB,Action Type: ,File size (
    bytes): 4216832,Device ID: SCSI\
    Disk&Ven_ATA&Prod_SAMSUNG_SSD_
    PM83\4&27c82505&0&000000