<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IBM Siteprotector. in Security</title>
    <link>https://community.splunk.com/t5/Security/IBM-Siteprotector/m-p/73986#M2468</link>
    <description>&lt;P&gt;In order to ingest IBM siteprotector data into Splunk you will first of all need to configure logging of events under the Siteprotector mgmt. platform to do this :&lt;BR /&gt;
Open siteprotector console&lt;BR /&gt;
Right click your event collector&lt;BR /&gt;
Select properties&lt;BR /&gt;
Select agent properties&lt;BR /&gt;
Under event collector logging "enable event logging to log files" and set your log retention period&lt;BR /&gt;
Save policy&lt;BR /&gt;
This will then write your IDS events to the file you have selected&lt;BR /&gt;
To then send logs to Splunk Install universal forwarder on the Event collectors and configure to obtain and send logs from the directory specified&lt;/P&gt;</description>
    <pubDate>Tue, 26 Sep 2017 11:39:45 GMT</pubDate>
    <dc:creator>MARKFOULKES</dc:creator>
    <dc:date>2017-09-26T11:39:45Z</dc:date>
    <item>
      <title>IBM Siteprotector.</title>
      <link>https://community.splunk.com/t5/Security/IBM-Siteprotector/m-p/73979#M2461</link>
      <description>&lt;P&gt;Anybody use splunk to index IBM(ISS) SiteProtector events.  Is there a syslog configuraton for Siteprotector?  It has a sql backend for all events and can send traps, but traps are only generated for alerts and not every IPS event is an alert.  My customer is looking for a forensic archive of IDS/IPS events in Splunk.&lt;/P&gt;

&lt;P&gt;Dave Croteau&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2010 22:50:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/IBM-Siteprotector/m-p/73979#M2461</guid>
      <dc:creator>davecroto</dc:creator>
      <dc:date>2010-10-20T22:50:11Z</dc:date>
    </item>
    <item>
      <title>Re: IBM Siteprotector.</title>
      <link>https://community.splunk.com/t5/Security/IBM-Siteprotector/m-p/73980#M2462</link>
      <description>&lt;P&gt;This should be possible with a &lt;A href="http://www.splunk.com/base/Documentation/latest/Admin/Setupcustom%28scripted%29inputs" rel="nofollow"&gt;custom scripted input&lt;/A&gt; that will pull the event data from the database. Not sure if anybody has done it before though.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2010 22:53:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/IBM-Siteprotector/m-p/73980#M2462</guid>
      <dc:creator>ftk</dc:creator>
      <dc:date>2010-10-20T22:53:30Z</dc:date>
    </item>
    <item>
      <title>Re: IBM Siteprotector.</title>
      <link>https://community.splunk.com/t5/Security/IBM-Siteprotector/m-p/73981#M2463</link>
      <description>&lt;P&gt;It's been a while, but there used to be a way to enable (Event Collector?) logging to a text file in SiteProtector. &lt;/P&gt;

&lt;P&gt;It may call them "trace" logs - I can't remember now.&lt;/P&gt;

&lt;P&gt;Once you have the text files, indexing them with Splunk is pretty trivial. &lt;/P&gt;

&lt;P&gt;&lt;/P&gt;&lt;HR /&gt;&lt;P&gt;&lt;/P&gt;

&lt;P&gt;Found some more information in my old notes. Things may have changed in more recent versions of SiteProtector, but look for trace file settings under Advanced Event Collector Configuration, and/or look for the Event Archiver.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2010 23:38:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/IBM-Siteprotector/m-p/73981#M2463</guid>
      <dc:creator>southeringtonp</dc:creator>
      <dc:date>2010-10-20T23:38:22Z</dc:date>
    </item>
    <item>
      <title>Re: IBM Siteprotector.</title>
      <link>https://community.splunk.com/t5/Security/IBM-Siteprotector/m-p/73982#M2464</link>
      <description>&lt;P&gt;Would custom scripted Input scale for every IDS/IPS Event?  Perhaps hundreds of thousands of events per hour?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2010 00:18:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/IBM-Siteprotector/m-p/73982#M2464</guid>
      <dc:creator>davecroto</dc:creator>
      <dc:date>2010-10-21T00:18:44Z</dc:date>
    </item>
    <item>
      <title>Re: IBM Siteprotector.</title>
      <link>https://community.splunk.com/t5/Security/IBM-Siteprotector/m-p/73983#M2465</link>
      <description>&lt;P&gt;hmm, that's a great question, and I am not sure to be honest -- basically you would have a python script that runs a query on your database. Not sure how much data that can handle.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2010 00:38:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/IBM-Siteprotector/m-p/73983#M2465</guid>
      <dc:creator>ftk</dc:creator>
      <dc:date>2010-10-21T00:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: IBM Siteprotector.</title>
      <link>https://community.splunk.com/t5/Security/IBM-Siteprotector/m-p/73984#M2466</link>
      <description>&lt;P&gt;The Event Collector generates a .txt file before batch-importing to the database.&lt;/P&gt;

&lt;P&gt;We used a monitor on the directory hierarchy. Ours is located (I think this can be configured) in C:\Program Files\ISS\SiteProtector\Event Archiver\EventLogDir (note, below, we mounted that via a network share because we didn't want to install a universal forwarder on the box.&lt;/P&gt;

&lt;P&gt;ignoreOlderThan is necessary not to overwhelm lsof on restart.&lt;/P&gt;

&lt;P&gt;So, inputs.conf looks like this:&lt;BR /&gt;
[monitor:////mnt/server/eventlogdir]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
followTail = 0&lt;BR /&gt;
sourcetype = iss-realsecure&lt;BR /&gt;
ignoreOlderThan = 1d&lt;BR /&gt;
whitelist = .txt&lt;/P&gt;</description>
      <pubDate>Mon, 01 Aug 2011 20:10:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/IBM-Siteprotector/m-p/73984#M2466</guid>
      <dc:creator>drbones</dc:creator>
      <dc:date>2011-08-01T20:10:21Z</dc:date>
    </item>
    <item>
      <title>Re: IBM Siteprotector.</title>
      <link>https://community.splunk.com/t5/Security/IBM-Siteprotector/m-p/73985#M2467</link>
      <description>&lt;P&gt;Hello drbones,&lt;/P&gt;

&lt;P&gt;May I know how you granted permission for forwarder agent on the  mounted drive. Whether your Site Protector system and forwarder installed machines is part of same domain. &lt;BR /&gt;
In our case Site protector is not in domain hence forwarder could not read the mounted drive due to permission issues.  &lt;/P&gt;</description>
      <pubDate>Mon, 27 Feb 2017 08:01:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/IBM-Siteprotector/m-p/73985#M2467</guid>
      <dc:creator>sirajnp</dc:creator>
      <dc:date>2017-02-27T08:01:22Z</dc:date>
    </item>
    <item>
      <title>Re: IBM Siteprotector.</title>
      <link>https://community.splunk.com/t5/Security/IBM-Siteprotector/m-p/73986#M2468</link>
      <description>&lt;P&gt;In order to ingest IBM siteprotector data into Splunk you will first of all need to configure logging of events under the Siteprotector mgmt. platform to do this :&lt;BR /&gt;
Open siteprotector console&lt;BR /&gt;
Right click your event collector&lt;BR /&gt;
Select properties&lt;BR /&gt;
Select agent properties&lt;BR /&gt;
Under event collector logging "enable event logging to log files" and set your log retention period&lt;BR /&gt;
Save policy&lt;BR /&gt;
This will then write your IDS events to the file you have selected&lt;BR /&gt;
To then send logs to Splunk Install universal forwarder on the Event collectors and configure to obtain and send logs from the directory specified&lt;/P&gt;</description>
      <pubDate>Tue, 26 Sep 2017 11:39:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/IBM-Siteprotector/m-p/73986#M2468</guid>
      <dc:creator>MARKFOULKES</dc:creator>
      <dc:date>2017-09-26T11:39:45Z</dc:date>
    </item>
  </channel>
</rss>

