Configuring the McAfee Windows Event Collector Management Utility *Also can provide client transmission of other non-windows log files*

Similar documents
August 22, 2006 IPRO Tech Client Services Tip of the Day. Concordance and IPRO Camera Button / Backwards DB Link Setup

USER MANUAL. RoomWizard Administrative Console

Campuses that access the SFS nvision Windows-based client need to allow outbound traffic to:

Exosoft Backup Manager

Launching Xacta 360 Marketplace AMI Guide June 2017

These tasks can now be performed by a special program called FTP clients.

Macquarie CMT download. Instructions to download information from the Macquarie CMT Your.Clients website

Tips For Customising Configuration Wizards

HPE AppPulse Mobile. Software Version: 2.1. IT Operations Management Integration Guide

Please contact technical support if you have questions about the directory that your organization uses for user management.

REFWORKS: STEP-BY-STEP HURST LIBRARY NORTHWEST UNIVERSITY

Trimble Survey GNSS Firmware Version 4.81 (July 2013)

Enabling Your Personal Web Page on the SacLink

Firmware Download Anybus X-gateway Modbus-TCP

CounterSnipe Software Installation Guide Software Version 10.x.x. Initial Set-up- Note: An internet connection is required for installation.

TechSmith Relay 5.1.5

Admin Report Kit for Exchange Server

Case Metrics Guide. January 11, 2019 Version For the most recent version of this document, visit our documentation website.

Installing Photran with Eclipse (MinGW or Cygwin)

ROCK-POND REPORTING 2.1

The screenshots/advice are based on upgrading Controller 10.1 RTM to 10.1 IF6 on Win2003

Getting Started with the SDAccel Environment on Nimbix Cloud

Refreshing Axiom TEST with a Current Copy of Production Axiom EPM June 20, 2014

Manual for installation and usage of the module Secure-Connect

Single File Upload Guide

Enterprise Installation

Dear Milestone Customer,

SAS Hot Fix Analysis, Download and Deployment Tool

TRAINING GUIDE. Overview of Lucity Spatial

FollowMe. FollowMe. Q-Server Quick Integration Guide. Revision: 5.4 Date: 11 th June Page 1 of 26

Able2Extract Server 3.0. User Guide

Sircon User Guide A Guide to Using the Vertafore Sircon Self-Service Portal

Migrating iway Data Quality Server Plans and Components on Windows

Client Configurations

Integrating QuickBooks with TimePro

FedVTE Training Advisor Guide

CaseWare Working Papers. Data Store user guide

RISKMAN REFERENCE GUIDE TO USER MANAGEMENT (Non-Network Logins)

Quick Installation Guide

ClubRunner. Volunteers Module Guide

CONFIGURING UUM . Android. You will need the following information to set up UUM

istartsmart 3.5 Upgrade - Installation Instructions

TDR and Trend Micro. Integration Guide

Table of Contents. WipeDrive Enterprise Logging, March Logging Settings... 3 Log Format Types Audit Log Destination Options...

OASIS SUBMISSIONS FOR FLORIDA: SYSTEM FUNCTIONS

Release Notes. Dell SonicWALL Security firmware is supported on the following appliances: Dell SonicWALL Security 200

Using the Swiftpage Connect List Manager

PAY EQUITY HEARINGS TRIBUNAL. Filing Guide. A Guide to Preparing and Filing Forms and Submissions with the Pay Equity Hearings Tribunal

Repstor custodian. On Premise Pre-Requisites. Document Version 1.1 January 2017

Upgrade Guide. Medtech Evolution Specialist. Version 1.11 Build (October 2018)

Upgrade Guide. Medtech Evolution General Practice. Version 1.9 Build (March 2018)

Secure File Transfer Protocol (SFTP) Interface for Data Intake User Guide

ONTARIO LABOUR RELATIONS BOARD. Filing Guide. A Guide to Preparing and Filing Forms and Submissions with the Ontario Labour Relations Board

WorldShip PRE-INSTALLATION INSTRUCTIONS: INSTALLATION INSTRUCTIONS: Window (if available) Install on a Single or Workgroup Workstation

Using the Swiftpage Connect List Manager

Troubleshooting of network problems is find and solve with the help of hardware and software is called troubleshooting tools.

Wave IP 4.5. CRMLink Desktop User Guide

Creating an Online Account

Xerox Security Bulletin XRX12-007

Sonic PDF Server 3.0. User Guide

BMC Remedyforce Integration with Remote Support

Firmware Upgrade Wizard v A Technical Guide

Transferring dongle licenses online

BI Publisher TEMPLATE Tutorial

escreen Setup and Usage Instructions

Samsung Galaxy -Exchange ActiveSync Setup

Graduate Application Review Process Documentation

Moving your MedicalDirector Clinical / PracSoft Data to a New Server

INSERTING MEDIA AND OBJECTS

UPGRADING TO DISCOVERY 2005

Avigilon Control Center Server User Guide. Version 6.8

Avigilon Control Center Server User Guide. Version 6.4

Technical Paper. Installing and Configuring SAS Environment Manager in a SAS Grid Environment with a Shared Configuration Directory

Apache Solr for FSI SERVER. User Manual. Version 4.5

ENSC 351 software installation instructions

Tips and Tricks in Word 2000 Part II. Presented by Carla Torgerson

CMS and e-commerce Solutions. version 1.0. Please, visit us at: or contact directly by

HW4 Software Version 3.4.1

HW4 Software version 3. Device Manager and Data Logging LOG-RC Series Data Loggers

UBC BLOGS NSYNC PLUGIN

User Guide. Table Of Contents. Logging In. Job Search. Job Information. Site Search & Logging A Job. Customer Search. Job Dashboard.

HP Universal CMDB. Software Version: Backup and Recovery Guide

IFSP PDF Upload/Download Guidance

Planning, installing, and configuring IBM CMIS for Content Manager OnDemand

1 Getting and Extracting the Upgrader

Upgrading Kaltura MediaSpace TM Enterprise 1.0 to Kaltura MediaSpace TM Enterprise 2.0

TRAINING GUIDE. Lucity Mobile

Guide to getting started in J2ME for the Motorola A780 phone

McAfee Endpoint Upgrade Assistant 2.2

Imagine for MSDNAA Student SetUp Instructions

Quick Start Guide. Basic Concepts. DemoPad Designer - Quick Start Guide

BMC Remedyforce Integration with Bomgar Remote Support

File Share Navigator Online

Element Creator for Enterprise Architect

mconnect Lead Management System 2.0

Configuring Database & SQL Query Monitoring With Sentry-go Quick & Plus! monitors

Technical Paper. Installing and Configuring SAS Environment Manager in a SAS Grid Environment

ClassFlow Administrator User Guide

User Guide. Document Version: 1.0. Solution Version:

Class Roster. Curriculum Class Roster Step-By-Step Procedure

Transcription:

Cnfiguring the McAfee Windws Event Cllectr Management Utility *Als can prvide client transmissin f ther nn-windws lg files* Utility Install 1. Dwnlad the MFE Nitr Windws Agent (chse latest versin) https://secure.mcafee.cm/apps/dwnlads/my-prducts/cmpnent-prductlist.aspx?regin=us (must have active Grant # with access t SIEM sftware) 2. Run the Setup_x86_[versin #].exe file n yur windws client, r use the WindwsEventCllectrInstaller_x86_[versin #].msi t deply via 3 rd party tls. 3. Click I Agree fr licensing Terms 4. Define any custm install path r chse default, and click Next

5. Enter in the McAfee ERC (receiver) IP address f the cllectr yu want t receive the lgs, adjust the MEF prt if necessary (default 8081 *nte yu need t knw this as yu must define as a listening interface n yur cllectr), chse the SSL ptin if yu require event lgs t be encrypted in transmissin, and click Next. 6. Chse whether r nt yu want the utility t pen after install r nt, and click Finish. Cnfigure Generic Lg File Transmissin 1. Click n Start>Prgrams>McAfee>Event Cllectr Management Utility

2. Click t Highlight EventCllectr and then click the + in the tp bar t add a new Event Cllectin Grup (Grups are used t grup tgether multiple lg types). 3. Prvide the fllwing fr yur grup: Name f Grup - (Use a semi descriptive name f the purpse f this event cllectin grup) Accunt Used t Access Hst Lgs This can be a general accunt that yu define at the default event cllectr level, r can be specific t this lg file lcatin, when cmplete yu can click Validate Against Agent t test the credentials access Debug Lg Level Depending n what yu are ding here, if this is just a flat file, this ptin desn t matter as it will transfer the entire file (*this is relevant if yu are pulling actual lgs frm a windws event viewer)

Click Apply 4. If yu get a dialg bx t Crrect Errrs yu will either need t mdify the cnfiguratin t ensure yu can cnnect, r click n until yu reslve the issue and then later re-enable the grup. 5. Once yu have yur new grup created, yu can then highlight the grup and then click the + ptin t add a hst t yur grup. 6. Cnfigure the Hst Infrmatin

Enter in the Hstname/IP address f the hst yu are cnfiguring Check the Hst Enabled bx (if the hst is nt live, yu will need t cme back in and enable nce it is) Chse the accunt with Access t Hst (if different than the grup settings abve) Chse the Lg cnfiguratin (fr a flat lgfile, yu will chse Generic Lg Tail as seen belw) Give the cnfiguratin a name (This is just a descriptive name that yu chse) Enter in the Data Surce IP f where the lgs are lcated Enter in the full directry path t the lgs (can be either lcal directry r full UNC path if remte directry) Enter the lg file name (Wildcard can be used IE: *.lg fr all files ending in.lg) Chse if yu want the agent t tail frm the beginning f the file r end (can g back in time if the file is nly appended t **be careful if lg files are nt verwritten ften as ging back in time puts larger indexing lad n McAfee ESM DB**) If the lg cntains Multi-Line Events select the check bx If the lg cntains multi-line events yu must chse the delimiter fr the file read If the lg delimiter yu have defined is a regex value, then yu must check the Regex bx If the events are multi-line, then yu need t specify if knwn hw many lines are included in a single event 7. Once everything is defined, then click the Service ptin frm the tp menu bar, and chse t Start the agent service

8. Ensure that all Grups and Hsts within the grups that yu are lking t have cllectin n are selected as Enabled and then yu shuld see Service Started in the bttm left crner f the screen. 9. Yu have nw cmpleted the cnfiguratin f a Generic Lg.