Log Collection Event Sources Tab

Document created by RSA Information Design and Development on Sep 11, 2017Last modified by RSA Information Design and Development on Oct 12, 2017
Version 7Show Document
  • View in full screen mode
  

Use the Event Sources tab to configure the AWS (CloudTrail), Check Point, File, ODBC, SDEE, SNMP, Syslog, SNMP, VMware,  Windows, and Windows Legacy event sources.

To access the Event Sources tab, go to ADMIN > Services > select Log Collection service > View > Config > Event Sources) .

Workflow

This workflow illustrates the basic tasks needed to start collecting events through Log Collection.

Log Collection workflow shows the basic tasks for collecting events.

What do you want to do?

                                                               
RoleI want to...Documentation
Administrator

Configure AWS (CloudTrail) event sources.

Configure AWS (CloudTrail) Event Sources in NetWitness Suite

Administrator Configure CheckPoint event sources.

Configure Check Point Event Sources in NetWitness Suite

Administrator

Configure File event sources.

Configure File Event Sources in NetWitness Suite

AdministratorConfigure ODBC event sources.Configure ODBC Event Sources in NetWitness Suite

Administrator

Configure SDEE event sources.

Configure SDEE Event Sources in NetWitness Suite

AdministratorConfigure SNMP event sources.Configure SNMP Event Sources in NetWitness Suite

Administrator

Configure Syslog event sources.

Configure Syslog Event Sources for Remote Collector

Administrator

Configure VMware event sources.

Configure VMware Event Sources in NetWitness Suite

AdministratorConfigure Windows event sources.Configure Windows Event Sources in NetWitness Suite

Administrator

Configure Windows Legacy event sources.

Windows Legacy and NetApp Collection Configuration

Related Topics

Quick Look

The Config view has two drop-down menus:

  • The left-most menu lists all of the available collection protocols.

    CheckPoint protocol is selected from Collection Protocols drop-down menu.

  • The right-most menu has two choices: Config and Filter.

    Example shows Config and Filter options.

 

The Config view in the Event sources tab has two panels: Event Categories and Sources.

Note: For details on the Filter menu item, see Configure Event Filters for a Collector.

Event Source Types Menu

The Log Collector Event Sources tab has a two-box, drop-down menu in which you select the collection protocol and any supporting parameters for that protocol.

In the left box, you select one of the following protocols: Check Point, File, ODBC, Plugins, SDEE, SNMP, SNMP, VMware, Windows, and Windows Legacy.

In the right box, you select:

  • Config to configure the generic event source parameters for the type you selected in the left drop-down.  All generic Config panels have a toolbar with these options:

    • Add, Edit, and Delete
    • Import  (also Import Source, Import DSN)
    • Export (also Export Source, Export DSN)
  • For ODBC, SNMP, and Windows only:
    • For ODBC, DSNs to configure
    • For SNMP, SNMP v3 User Manager
    • For Windows, Kerberos Realm Configuration

Selecting an option displays a configuration panel where you configure the collection parameters for the event source. The configuration panels are slightly different for different event sources and are described separately.

Event Categories Panel

Once you select a collection protocol, the Event Categories panel is populated with all of the event sources that you have configured for that collection protocol. For example, the following image shows ODBC event sources that have been configured:

Example of Event Categories panel.

The Event Categories panel provides a way to add or delete event source types.

                     
1Displays the Available Event Source Types dialog from which you select the event source type for which you want to define parameters.
2Deletes the selected event source types from the Event Categories panel.
3

Selects event source types.

4Displays the name of the event source types that you have added.

Sources Panel

The Sources panel lists the values of the parameters for the selected event source type. For details, see the individual collection protocol topics.

You are here
Table of Contents > Reference > Tabs > Log Collection Event Sources Tab

Attachments

    Outcomes