Security Compliance
Integrate Websense with SolarWinds SEM
This article provides steps for configuring Websense Enterprise to send logs to your SEM appliance using SNMP, and configuring your SEM appliance to accept the logs and process them for storage and monitoring.
First published date
Last published date
Overview
Note: Starting with Websense v6.1, Websense sends system events to an SNMP server, but it continues to log activity events to a local database.
Product section
Resolution
Requirements
- Websense Enterprise - Corporate Edition v6.1 or later
- Websense Client Policy Manager (CPM)
- Websense Usage Monitor
Configure Websense to send log messages to the SEM appliance
- Open Websense Manager.
- On the Network tab, navigate to Server > Settings.
- In the Settings form, click Alerts and Notifications in the left pane.
- In the Maximum usage alerts per event field on the Configuration tab, enter 9999.
- Under SNMP Alert Settings, select SNMP Alerts.
- In the IP Address field, enter the IP address of your SEM appliance.
- Click the System Alerts tab, and then select SNMP for every row.
- Click the Category Usage Alerts tab.
- Set the Occurrence to 1 Time for each row except the Miscellaneous Uncategorized row.
- Set the Occurrence to 100 Times or greater for the Miscellaneous Uncategorized row.
- Select SNMP for each category for which you want to receive an alert.
- Click the Protocol Usage Alerts tab and set the Occurrence to 1 Time for each row.
- Select SNMP for each protocol for which you want to receive an alert.
- Click OK, and then Done.
Configure the Client Policy Manager for use with the SEM appliance
- Open Websense Manager.
- On the Desktop tab, navigate to Server > Settings.
- In the Settings form, click Alerts and Notifications in the left pane.
- Under Configure alerting modes on the Configuration tab, select SNMP.
- In the IP Address field, enter the IP address of your SEM appliance.
- Click the System Alerts tab and select SNMP for every row.
- Click the Usage Alerts tab.
- Set the Occurrence to 1 Time for each row.
- Select SNMP for each row.
- Click OK.
Configure the SEM appliance to accept logs from Websense
To configure your SEM Manager to accept SNMP traps:- Connect to your SEM virtual appliance using either the vSphere console view, or an SSH client like PuTTY.
- If you are using an SSH client, log in to your SEM virtual appliance using your CMC credentials.
- At the
cmc>prompt, enterservice. - At the
cmc::scm#prompt, enterenablesnmp. - To confirm your entry, press Enter.
- After you see the following message, enter
exitto return to thecmc>prompt:
Done starting the SNMP service- Enter
exitto log out of your SEM virtual appliance.
Configure the Websense Web Filter and Websense Web Security connector on the SEM Manager
Flash console- On the SEM console toolbar, navigate to Manage > Appliances, and then log in to your SEM Manager as an administrator.
- Next to the SEM Manager, click the gear icon, and then select Connectors.
- In the Connector Configuration window, enter
Websense Web Filterin the search box at the top of the Refine Results pane. - Next to the Websense Web Filter and Websense Web Security connector, click the gear icon, and then select New.
- Enter a custom Alias or accept the default.
- If you are finished configuring the connector, click Save.
- Next to the new connector, click the gear icon (denoted by an icon in the Status column), and then click Start.
- To exit the Connector Configuration window, click Close.
- In the SEM Events Console, navigate to Nodes > Manager Connectors.
- In the search box, enter websense.
- Select the Websense Web Filter And Websense Web Security connector, and then click Add Connector.
- Enter a new name, or maintain the default, and then click Add.
- Under Configured connectors, select the connector, and then click Start.
Disclaimer: Please note, any content posted herein is provided as a suggestion or recommendation to you for your internal use. This is not part of the SolarWinds software or documentation that you purchased from SolarWinds, and the information set forth herein may come from third parties. Your organization should internally review and assess to what extent, if any, such custom scripts or recommendations will be incorporated into your environment. You elect to use third party content at your own risk, and you will be solely responsible for the incorporation of the same, if any.