Security Compliance

Integrate SecureSphere logs to monitor in SEM

This article provides information on how to configure SecureSphere Data Loss Prevention appliance connectors to monitor their logs in SEM.

First published date

11/1/2019 9:50 AM

Last published date

11/1/2019 9:50 AM

Overview

This article provides information on how to configure a SecureSphere syslog connector in SEM. They provide various types of solutions like Data Loss Prevention, DB Gateway and WAF etc. To learn more about the company and the products they currently offer please refer to:https://www.imperva.com/products/securesphere/ (© 2019 Imperva, available at https://www.imperva.com/, obtained on November 18, 2019). 


 

Product section

Security Event Manager

Cause

NA

Resolution

SEM Flash console
  1. Log in to the SEM web console.
  2. On the SEM web console menu bar, navigate to Manage > Appliances, and then click the gear icon next to the manager to open appliance connector pane:

  3. Search for SecureSphere to filter the results as shown below. Click the gear icon for the type of SecureSphere device logs you want to monitor.

  4. In this example we will select the first connector, and then click the gear icon to create new connector which brings up the new connector details pane.

  5. Ensure the log file path highlighted above is correct and matches what is configured on the SecureSphere Data Loss Prevention console and leave other settings untouched. Optionally, you can change the Alias name if you want to.
  6. Once you are satisfied with the connector configuration, click Save at the top right to save the changes. The new connector is created and is in the stopped state as shown below.

  7. Click the gear icon besides the newly created connector, and then click start to start the collector, which should look like this:


SEM HTML5 console (versions 6.6 and newer)
  1. In the SEM Events Console, navigate to Nodes > Manager Connectors.
  2. In the search box, enter SecureSphere.
  3. Select the SecureSphere Data Loss Prevention connector, and then click Add Connector.
  4. Ensure the log file path is correct, and matches what is configured in the SecureSphere Data Loss Prevention console. Optionally, you can change the name.
  5. Click Add.
  6. Under Configured connectors, select the connector, and then click Start. 

 

To quickly see the data from this newly created connector, please refer to Create filters in the SEM Events Console.

If you can’t see any events from SecureSphere devices, then follow the Troubleshoot network device logging or syslog device logging in SEM.

Disclaimer: Please note, any content posted herein is provided as a suggestion or recommendation to you for your internal use. This is not part of the SolarWinds software or documentation that you purchased from SolarWinds, and the information set forth herein may come from third parties. Your organization should internally review and assess to what extent, if any, such custom scripts or recommendations will be incorporated into your environment.  You elect to use third party content at your own risk, and you will be solely responsible for the incorporation of the same, if any.