RSA NetWitness Logs. Microsoft Network Policy Server. Event Source Log Configuration Guide. Last Modified: Thursday, June 08, 2017

Similar documents
RSA NetWitness Logs. Microsoft System Center Configuration Manager. Event Source Log Configuration Guide. Last Modified: Thursday, June 08, 2017

RSA NetWitness Logs. Microsoft SharePoint Server. Event Source Log Configuration Guide. Last Modified: Friday, June 02, 2017

RSA NetWitness Logs. Microsoft Forefront Endpoint Protection. Event Source Log Configuration Guide. Last Modified: Monday, November 13, 2017

RSA NetWitness Logs. Oracle Directory Server. Event Source Log Configuration Guide. Last Modified: Thursday, June 29, 2017

RSA NetWitness Logs. GlobalSCAPE Enhanced File Transfer (EFT) Server. Event Source Log Configuration Guide. Last Modified: Thursday, May 25, 2017

RSA NetWitness Logs. Radiator Radius Server. Event Source Log Configuration Guide. Last Modified: Thursday, November 2, 2017

RSA NetWitness Logs. McAfee Endpoint Encryption. Event Source Log Configuration Guide. Last Modified: Friday, June 02, 2017

RSA NetWitness Logs. Citrix Access Gateway Last Modified: Thursday, May 11, Event Source Log Configuration Guide

RSA NetWitness Logs. Juniper Networks NetScreen-Security Manager Last Modified: Thursday, May 25, Event Source Log Configuration Guide

RSA NetWitness Logs. Microsoft Exchange Server. Event Source Log Configuration Guide. Last Modified: Thursday, November 2, 2017

RSA NetWitness Logs. Tripwire Enterprise. Event Source Log Configuration Guide. Last Modified: Friday, November 3, 2017

RSA NetWitness Logs. Tenable Nessus. Event Source Log Configuration Guide. Last Modified: Wednesday, August 09, 2017

RSA NetWitness Logs. EMC Isilon. Event Source Log Configuration Guide. Last Modified: Tuesday, October 31, 2017

RSA NetWitness Logs. Oracle iplanet Web Server. Event Source Log Configuration Guide. Last Modified: Tuesday, May 09, 2017

RSA NetWitness Logs. Microsoft Network Access Protection. Event Source Log Configuration Guide. Last Modified: Thursday, May 18, 2017

RSA NetWitness Logs. Trend Micro InterScan Messaging Security Suite. Event Source Log Configuration Guide. Last Modified: Tuesday, April 25, 2017

RSA NetWitness Logs SQUID. Event Source Log Configuration Guide. Last Modified: Thursday, October 12, 2017

RSA NetWitness Logs. Oracle Audit Vault and Database Firewall. Event Source Log Configuration Guide

RSA NetWitness Logs. EMC Ionix Unified Infrastructure Manager. Event Source Log Configuration Guide

RSA NetWitness Logs. VMware vcenter Server. Event Source Log Configuration Guide. Last Modified: Thursday, November 30, 2017

RSA NetWitness Logs IBM DB2. Event Source Log Configuration Guide. Last Modified: Friday, November 17, 2017

RSA NetWitness Logs. Apache HTTP Server. Event Source Log Configuration Guide. Last Modified: Friday, November 3, 2017

RSA NetWitness Logs. EMC Data Domain. Event Source Log Configuration Guide

RSA NetWitness Logs. F5 Big-IP Access Policy Manager. Event Source Log Configuration Guide. Last Modified: Friday, May 12, 2017

RSA NetWitness Logs. IBM ISS SiteProtector. Event Source Log Configuration Guide. Last Modified: Monday, May 22, 2017

RSA NetWitness Logs. EMC Symmetrix Solutions Enabler. Event Source Log Configuration Guide. Last Modified: Friday, April 21, 2017

RSA NetWitness Logs. McAfee Data Loss Prevention Endpoint. Event Source Log Configuration Guide. Last Modified: Thursday, May 25, 2017

RSA NetWitness Logs. Citrix XenMobile EMM Suite Last Modified: Wednesday, January 25, Event Source Log Configuration Guide

RSA NetWitness Logs. Bit9 Security Platform. Event Source Log Configuration Guide. Last Modified: Friday, May 05, 2017

RSA NetWitness Logs. VMware ESX/ESXi. Event Source Log Configuration Guide. Last Modified: Tuesday, November 7, 2017

RSA NetWitness Logs. Citrix XenApp. Event Source Log Configuration Guide

RSA NetWitness Logs. ManageEngine NetFlow Analyzer. Event Source Log Configuration Guide. Last Modified: Monday, March 06, 2017

RSA NetWitness Logs. McAfee Web Gateway. Event Source Log Configuration Guide. Last Modified: Wednesday, October 11, 2017

RSA NetWitness Logs. F5 Big-IP Application Security Manager. Event Source Log Configuration Guide. Last Modified: Friday, May 12, 2017

RSA NetWitness Logs. Imperva SecureSphere. Event Source Log Configuration Guide. Last Modified: Monday, May 22, 2017

RSA NetWitness Logs. Trend Micro OfficeScan and Control Manager. Event Source Log Configuration Guide. Last Modified: Thursday, November 30, 2017

RSA NetWitness Logs. DenyAll Web Application Firewall. Event Source Log Configuration Guide. Last Modified: Thursday, November 2, 2017

RSA NetWitness Logs. Apache Tomcat Server. Event Source Log Configuration Guide. Last Modified: Friday, November 3, 2017

RSA NetWitness Logs. Bind DNS. Event Source Log Configuration Guide. Last Modified: Thursday, October 19, 2017

RSA NetWitness Logs. Juniper Networks NetScreen ScreenOS Last Modified: Wednesday, November 8, Event Source Log Configuration Guide

RSA NetWitness Logs. Airtight Management Console. Event Source Log Configuration Guide. Last Modified: Thursday, May 04, 2017

RSA NetWitness Logs. Microsoft Windows. Event Source Log Configuration Guide. Last Modified: Thursday, October 5, 2017

RSA NetWitness Logs. IBM Tivoli Identity Manager. Event Source Log Configuration Guide. Last Modified: Monday, March 06, 2017

RSA NetWitness Logs. Cisco Adaptive Security Appliance Last Modified: Wednesday, November 8, Event Source Log Configuration Guide

RSA NetWitness Logs. Cisco Meraki. Event Source Log Configuration Guide. Last Modified: Monday, November 13, 2017

RSA NetWitness Logs. Symantec DLP Last Modified: Thursday, April 12, Event Source Log Configuration Guide

RSA NetWitness Logs. IBM WebSphere DataPower. Event Source Log Configuration Guide. Last Modified: Friday, January 5, 2018

RSA NetWitness Platform

RSA NetWitness Logs. Cisco Wireless LAN Controller. Event Source Log Configuration Guide

RSA NetWitness Logs. Linux. Event Source Log Configuration Guide. Last Modified: Thursday, October 12, 2017

RSA NetWitness Logs. Event Source Log Configuration Guide

RSA NetWitness Logs. Juniper Networks NetScreen Firewall Last Modified: Monday, October 9, Event Source Log Configuration Guide

RSA NetWitness Logs. Cisco IronPort Security Appliance. Event Source Log Configuration Guide. Last Modified: Thursday, January 19, 2017

RSA NetWitness Platform

RSA NetWitness Logs. IBM Domino. Event Source Log Configuration Guide. Last Modified: Thursday, October 19, 2017

RSA NetWitness Logs. Symantec Critical Systems Protection. Event Source Log Configuration Guide

RSA NetWitness Logs. F5 Big-IP Advanced Firewall Manager. Event Source Log Configuration Guide. Last Modified: Friday, May 12, 2017

RSA NetWitness Logs. MySQL Enterprise. Event Source Log Configuration Guide. Last Modified: Wednesday, November 15, 2017

RSA NetWitness Logs. Extreme Networks Switch Last Modified: Thursday, July 20, Event Source Log Configuration Guide

RSA NetWitness Logs. Sybase Adaptive Server Enterprise. Event Source Log Configuration Guide. Last Modified: Wednesday, November 29, 2017

Aruba Networks Mobility Controller

RSA NetWitness Logs. Cisco IronPort Web Security Appliance (WSA) Event Source Log Configuration Guide. Last Modified: Tuesday, January 9, 2018

RSA NetWitness Logs. RSA Web Threat Detection. Event Source Log Configuration Guide. Last Modified: Friday, April 14, 2017

RSA NetWitness Platform

RSA NetWitness Logs. Salesforce. Event Source Log Configuration Guide. Last Modified: Wednesday, February 14, 2018

RSA NetWitness Platform

RSA NetWitness Platform

RSA NetWitness Logs. Sophos Enterprise Console Last Modified: Friday, July 21, Event Source Log Configuration Guide

RSA NetWitness Logs. VMware NSX. Event Source Log Configuration Guide. Last Modified: Thursday, November 30, 2017

RSA NetWitness Platform

RSA NetWitness Logs. IBM AIX Last Modified: Thursday, November 2, Event Source Log Configuration Guide

RSA NetWitness Platform

RSA NetWitness Logs. IBM iseries Last Modified: Monday, May 22, Event Source Log Configuration Guide

RSA NetWitness Logs. F5 Big-IP Local Traffic Manager. Event Source Log Configuration Guide. Last Modified: Friday, May 12, 2017

BLUEPRINT TEAM REPOSITORY. For Requirements Center & Requirements Center Test Definition

Installation Guide Integrating Worksoft Certify with IBM Rational Quality Manager

ZENworks 2017 Patch Management Airgap Solution. 1 About the Airgap Solution. 2 Prerequisites. December 2017

RSA Via L&G Collector Data Sheet for Office365

RSA NetWitness Platform

HYCU SCOM Management Pack for F5 BIG-IP

RSA NetWitness Logs. McAfee Network Security Platform. Event Source Log Configuration Guide. Last Modified: Thursday, March 8, 2018

Avaya Contact Centre Control Manager Release 7.0 Service Pack 1 (ACCCM 7.0 SP1 or ACCCM 7.0.1)

RSA NetWitness Logs. Microsoft Azure NSG (Flow Logs) Event Source Log Configuration Guide. Last Modified: Monday, February 26, 2018

SPNEGO SINGLE SIGN-ON USING SECURE LOGIN SERVER X.509 CLIENT CERTIFICATES

How Do I Manage Active Directory

Sophos Transparent Authentication Suite Quick Start Guide. Product version: 2.0 Document date: Wednesday, July 05, 2017

LifeSize Control Installation Guide

HPE Enterprise Integration Module for SAP Solution Manager 7.1

SAS Model Manager 2.3

SCCM Plug-in User Guide. Version 3.0

Realms and Identity Policies

Configuring the Avaya B179 SIP Conference Phone with Avaya Aura Communication Manager 5.X and Avaya Aura Session Manager 6.X v1.0.

Managing the SSL Certificate for the ESRS HTTPS Listener Service Technical Notes P/N Rev 01 July, 2012

Dameware ADMINISTRATOR GUIDE. Version Last Updated: October 18, 2017

EMC ApplicationXtender Index Agent

Storage Manager 2018 R1. Installation Guide

Installing SQL Server Developer Last updated 8/28/2010

Working with SQL SERVER EXPRESS

HYCU SCOM Management Pack for F5 BIG-IP

FieldView. Management Suite

Transcription:

RSA NetWitness Logs Event Source Log Configuration Guide Microsoft Network Policy Server Last Modified: Thursday, June 08, 2017 Event Source Product Information: Vendor: Microsoft Event Source: Network Policy Server Versions: 3.2, 4.0 Additional Downloads: For File Collection: sftpagent.conf.msias For Windows Collection: useradd.vbs, rsa_sa_winevent_config.vbs RSA Product Information: Supported On: NetWitness Suite 10.0 and later Event Source Log Parser: msias Collection Method: File and Windows Event Logs Event Source Class.Subclass: Security.Access Control

You can configure RSA NetWitness Suite to collect logs from Microsoft Network Policy Server, using either File collection, Windows Eventing collection, or both. I. Configure Microsoft NPS II. Configure RSA NetWitness Suite for Windows and/or File Collection: Configure File Collection Configure Windows Collection 2

Configure Microsoft NPS This section describes how to set up the Microsoft Network Policy Server event source for Windows collection. To configure Microsoft NPS for Windows collection: 1. Start the Network Policy Server management utility. 2. Select the Remote Access Logging folder. 3. Double click on the Local File logging method. 4. On the Settings tab, ensure that the following boxes are selected: Accounting Requests Authentication Requests Periodic Status 5. On the Log File tab, confirm the following settings: In the Directory field, select C:\WINDOWS\system32\LogFile. In the Format field, select IAS (Legacy). In the Create a new log file field, select Daily. In the When disk is full delete older log files field, ensure the check box is selected. 3 Configure Microsoft NPS

Configure File Collection To configure Microsoft Network Policy Server for File collection, you must complete these tasks: I. Set Up the SFTP Agent II. Set up the File Service Note: To configure File Collection, you need a Log Collector that is at version 10.5.2 or later. Set Up the SFTP Agent To set up the SFTP Agent Collector, download the appropriate PDF from RSA Link: To set up the SFTP agent on Windows, see Install and Update SFTP Agent To set up the SFTP agent on Linux, see Configure SA SFTP Agent shell script Configure the Log Collector for File Collection Perform the following steps to configure the Log Collector for File collection. To configure the Log Collector for file collection: 1. In the NetWitness menu, select Administration > Services. 2. In the Services grid, select a Log Collector, and from the Actions menu, choose View > Config > Event Sources. 3. Select File/Config from the drop-down menu. The Event Categories panel displays the File event sources that are configured, if any. 4. In the Event Categories panel toolbar, click +. The Available Event Source Types dialog is displayed. Configure File Collection 4

5. Select the correct type from the list, and click OK. Select msias_tvm from the Available Event Source Types dialog. The newly added event source type is displayed in the Event Categories panel. 6. Select the new type in the Event Categories panel and click + in the Sources panel toolbar. 5 Configure the Log Collector for File Collection

The Add Source dialog is displayed. 7. Add a File Directory name, modify any other parameters that require changes, and click OK. 8. Stop and Restart File Collection. After you add a new event source that uses file collection, you must stop and restart the NetWitness File Collection service. This is necessary to add the key to the new event source. Configure the Log Collector for File Collection 6

Configure Windows Collection There are two parts to configuring Windows collection: I. Configure WinRM on the Windows Host II. Configure RSA NetWitness Suite for Windows Collection. Configure WinRM on a Windows Host This section describes a shortcut method to configure the Windows host. It assumes that you have the following two RSA scripts available: useradd: sets up a user account with the necessary permissions. RSA_SA_winevent_config.vbs: sets up the WinRM listener To set up and run the useradd script: 1. Open useradd.vbs for editing. 2. You need to enter your values for the following two parameters: User account: in the Name field, enter the name for the RSA user account. Domain: in the compname parameter, enter your domain name. Note: For the remainder of this document, we are using example values: rsalog for the user account, and dsnetworking.com for the domain name. 3. On the Windows host, open a Command Prompt, and run useradd: c:\program Files\scripts>useradd.vbs Note: You need to run the script as an administrator. The script prompts you to open the file. Click Yes to run the script and set up your user. To run the script to set up the WinRM listener: 1. On the Windows host, open a Command Prompt. 2. Navigate to the folder where the script is stored, and run it as follows: rsa_sa_winevent_config.vbs http The script prompts you with a series of information and verification screens: accept them as they appear, in order to have the script succeed. 7 Configure Windows Collection

This completes your set up on the Windows host. Next, you configure RSA NetWitness Suite. Configure RSA NetWitness Suite for Windows Collection In RSA NetWitness Suite, you need to configure the Kerberos Realm, and then add the Windows Event Source type. To configure the Kerberos Realm for Windows collection: 1. In the Security Analytics menu, select Administration > Services. 2. In the Services grid, select a Log Collector, and from the Actions menu, choose View > Config > Event Sources. 3. Select Windows/Kerberos Realm from the drop-down menu. 4. In the Kerberos Realm Configuration panel toolbar, click + to add a new realm. The Add Kerberos Domain dialog is displayed. 5. Fill in the parameters, using the guidelines below. Parameter Kerberos Realm Name KDC Host Name Details Enter the realm name, in all caps. For example, DSNETWORKING.COM. Note that the Mappings parameter is automatically filled with variations on the realm name. Enter the name of the Domain Controller. Do not use a fully qualified name here: just the host name for the DC. Note: Make sure that the log collector is configured as a DNS client for the corporate DNS server. Otherwise, the LC will not know how to find the Kerberos Realm. Admin Server (Optional) The name of the Kerberos Administration Server in FQDN format. 6. Click Save to add the Kerberos domain. Next, continue from the current screen to add a Windows Event Category and type. Configure RSA NetWitness Suite for Windows Collection 8

To configure the Windows Event Type: 1. Select Windows/Config from the drop-down menu. 2. In the Event Categories panel toolbar, click + to add a source. The Add Source dialog is displayed. 3. Fill in the parameters, using the guidelines below. Parameter Alias Authorization Method Channel User Name Password Max Events Per Cycle Polling Interval Details Enter a descriptive name. Choose Negotiate. For most event sources that use Windows collection, you want to collect from the Security, System, and Application channels. Enter the account name for the Windows user account that you set up earlier for communicating with Security Analytics. Note that you need to enter the full account name, which includes the domain. For example, rsalog@dsnetworking.com. Enter the correct password for the user account. (Optional). RSA recommends that you set this value to 0, which collects everything. (Optional). For most users, a value of 60 should work well. 4. Click OK to add the source. The newly added Windows event source is displayed in the Event Categories panel. 5. Select the new event source in the Event Categories panel. The Hosts panel is activated. 6. Click + in the Hosts panel toolbar. 9 Configure RSA NetWitness Suite for Windows Collection

7. Fill in the parameters, using the guidelines below. Parameter Event Source Address Details Enter the IP address for the Windows host. Port Accept the default value, 5985. Transport Mode Enabled Enter http. Ensure the box is checked. 8. Click Test Connection. Note: In Security Analytics versions prior to 10.4 patch 2, the Windows service had to be running in order for the test connection to work. In later versions, you should be able to successfully test the connection, even if the Windows service is not running. For more information on any of the previous steps, see the following Help topics in the Security Analytics User Guide: Configure Windows Collection: https://community.rsa.com/docs/doc-43410 Microsoft WinRM Configuration Guide: https://community.rsa.com/docs/doc-58163 Test and Troubleshoot Microsoft WinRM Guide: https://community.rsa.com/docs/doc-58164 Copyright 2017 EMC Corporation. All Rights Reserved. Trademarks RSA, the RSA Logo and EMC are either registered trademarks or trademarks of EMC Corporation in the United States and/or other countries. All other trademarks used herein are the property of their respective owners. Configure RSA NetWitness Suite for Windows Collection 10