Setup Guide

54
DellProtectedWorkspaceManagementServerInstallandConfigurev2.2
ConfiguringtheThreatsModulewiththeCorrectSYSLOGformat
TheDPWMSThreatsModuleisabletosendThreatReportinformationtoSIEMsystemsinafewdifferentformatsto
bettersuitthereceivingSIEMsystem.AvailableformatsareSplunk,Q1Labs,Arcsight andRSAEnvision.
Tosettheproperloggingformat,selectthePluginsmenufromtheThreatData
tab.
FromthePluginSettingsdialog,locatetheentryforformatsunderthealertsheaderandmakesurethatthe“Enabled”
boxischecked.Ifnot,checktheboxandrestarttheDPWMS(ims2)service.Now,modifythislinetothecorrectformat
(onlyoneshouldbeselected.Allfour
aredisplayedbydefault,andshouldbemodifiedtothecorrectselection):
sp=Splunk
q1=Q1Labs
arst=Archsight
env=RSAEnvision
Optionally,modifythelognameentrytocreateacustomsearchwordintheSYSLOGentry.Thislognameisincludingat
thebeginningoftheSYSLOGmessagesgeneratedbytheThreatsModule.
Pressthe“Save”buttonandclosethedialogoncethechangeshavebeenmade.