Para coletar eventos do H3C Comware Platform, ative as configurações de syslog e configure um host do log. H3C , Roteadores H3C , Dispositivos LAN Wireless H3C e Dispositivos de Segurança IP H3C são suportados pelo QRadar.
Procedimento
- Faça login na interface linha de comandos usando a porta do console, ou usando Telnet ou SSH.
Para obter mais informações sobre métodos de login, veja a seção Efetuando login na CLI no
guia de configuração para seus dispositivos H3C.
- Para acessar a visualização do sistema, digite o comando <system_name>
system-view .
- Para ativar as configurações de syslog, digite os comandos a seguir na ordem em que são
listados.
- info-center source default loghost deny
- info-center source AAA loghost level informational
- info-center source ACL loghost level informational
- info-center source FIPS loghost level informational
- info-center source HTTPD loghost level informational
- info-center source IKE loghost level informational
- info-center source IPSEC loghost level informational
- info-center source LOGIN loghost level informational
- info-center source LS loghost level informational
- info-center source PKI loghost level informational
- info-center source PORTSEC loghost level informational
- info-center source PWDCTL loghost level informational
- info-center source RADIUS loghost level informational
- info-center source SHELL loghost level informational
- info-center source SNMP loghost level informational
- info-center source SSHS loghost level informational
- info-center source TACACS loghost level informational
- info-center loghost <QRadar Event Collector IP>
514
- Para sair da visualização do sistema, digite o comando quit
<system_name> .