Security Compliance

Integrate Websense with SolarWinds SEM

This article provides steps for configuring Websense Enterprise to send logs to your SEM appliance using SNMP, and configuring your SEM appliance to accept the logs and process them for storage and monitoring.

First published date

11/29/2018 10:28 PM

Last published date

11/29/2018 10:28 PM

Overview

This article outlines the procedures for configuring Websense Enterprise to send logs to your Security Event Manager (formerly Log & Event Manager) appliance using SNMP, and configuring your SEM appliance to accept the logs and process them for storage and monitoring.

Note: Starting with Websense v6.1, Websense sends system events to an SNMP server, but it continues to log activity events to a local database.

Product section

Security Event Manager

Resolution

Requirements 

  • Websense Enterprise - Corporate Edition v6.1 or later
  • Websense Client Policy Manager (CPM)
  • Websense Usage Monitor

Configure Websense to send log messages to the SEM appliance 

  1. Open Websense Manager.
  2. On the Network tab, navigate to Server > Settings.
  3. In the Settings form, click Alerts and Notifications in the left pane.
  4. In the Maximum usage alerts per event field on the Configuration tab, enter 9999.
  5. Under SNMP Alert Settings, select SNMP Alerts.
  6. In the IP Address field, enter the IP address of your SEM appliance.
  7. Click the System Alerts tab, and then select SNMP for every row.
  8. Click the Category Usage Alerts tab.
  9. Set the Occurrence to 1 Time for each row except the Miscellaneous Uncategorized row.
  10. Set the Occurrence to 100 Times or greater for the Miscellaneous Uncategorized row.
  11. Select SNMP for each category for which you want to receive an alert.
  12. Click the Protocol Usage Alerts tab and set the Occurrence to 1 Time for each row.
  13. Select SNMP for each protocol for which you want to receive an alert.
  14. Click OK, and then Done.

Configure the Client Policy Manager for use with the SEM appliance

  1. Open Websense Manager.
  2. On the Desktop tab, navigate to Server > Settings.
  3. In the Settings form, click Alerts and Notifications in the left pane.
  4. Under Configure alerting modes on the Configuration tab, select SNMP.
  5. In the IP Address field, enter the IP address of your SEM appliance.
  6. Click the System Alerts tab and select SNMP for every row.
  7. Click the Usage Alerts tab.
  8. Set the Occurrence to 1 Time for each row.
  9. Select SNMP for each row.
  10. Click OK.

Configure the SEM appliance to accept logs from Websense 

​To configure your SEM Manager to accept SNMP traps:
  1. Connect to your SEM virtual appliance using either the vSphere console view, or an SSH client like PuTTY.
  2. If you are using an SSH client, log in to your SEM virtual appliance using your CMC credentials.
  3. At the cmc> prompt, enter service.
  4. At the cmc::scm# prompt, enter enablesnmp.
  5.  To confirm your entry, press Enter.
  6. After you see the following message, enter exit to return to the cmc> prompt:
Done starting the SNMP service
  1. Enter exit to log out of your SEM virtual appliance.

Configure the Websense Web Filter and Websense Web Security connector on the SEM Manager 

Flash console
  1. On the SEM console toolbar, navigate to Manage > Appliances, and then log in to your SEM Manager as an administrator.
  2. Next to the SEM Manager, click the gear icon, and then select Connectors.
  3. In the Connector Configuration window, enter Websense Web Filter in the search box at the top of the Refine Results pane.
  4. Next to the Websense Web Filter and Websense Web Security connector, click the gear icon, and then select New.
  5. Enter a custom Alias or accept the default.
  6. If you are finished configuring the connector, click Save.
  7. Next to the new connector, click the gear icon (denoted by an icon in the Status column), and then click Start.
  8. To exit the Connector Configuration window, click Close.
HTML5 console
  1. In the SEM Events Console, navigate to Nodes > Manager Connectors.
  2. In the search box, enter websense.
  3. Select the Websense Web Filter And Websense Web Security connector, and then click Add Connector.
  4. Enter a new name, or maintain the default, and then click Add.
  5. Under Configured connectors, select the connector, and then click Start.


Disclaimer: Please note, any content posted herein is provided as a suggestion or recommendation to you for your internal use. This is not part of the SolarWinds software or documentation that you purchased from SolarWinds, and the information set forth herein may come from third parties. Your organization should internally review and assess to what extent, if any, such custom scripts or recommendations will be incorporated into your environment.  You elect to use third party content at your own risk, and you will be solely responsible for the incorporation of the same, if any.