VMware VCLOUD REQUEST MANAGER 1.0.0 Uživatelská příručka

Procházejte online nebo si stáhněte Uživatelská příručka pro Sítě VMware VCLOUD REQUEST MANAGER 1.0.0. VMware VCLOUD REQUEST MANAGER 1.0.0 User`s guide Uživatelská příručka

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 39
  • Tabulka s obsahem
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 0
Technical white paper
HP CloudSystem Enterprise
Integrating security with HP ArcSight
Table of contents
Executive summary ...................................................................................................................................................................... 3
HP CloudSystem Enterprise overview ...................................................................................................................................... 3
HP CloudSystem Enterprise supply layer ............................................................................................................................ 3
HP CloudSystem Enterprise demand and delivery: HP Cloud Service Automation .................................................... 3
HP CloudSystem Enterprise components ........................................................................................................................... 4
HP ArcSight overview ................................................................................................................................................................... 4
Enterprise Security Manager .................................................................................................................................................. 4
HP ArcSight Logger ................................................................................................................................................................... 5
HP ArcSight Connectors ........................................................................................................................................................... 5
Typical deployment scenarios .................................................................................................................................................... 6
Sending events in RAW and CEF format to HP ArcSight Logger ..................................................................................... 6
Sending events to HP ArcSight Logger using Connectors ............................................................................................... 7
Sending events to HP ArcSight ESM using Connectors ..................................................................................................... 8
Devices ........................................................................................................................................................................................ 9
Grouping devices ....................................................................................................................................................................... 9
Forwarding events to HP ArcSight ESM.............................................................................................................................. 10
Protecting HP CloudSystem Enterprise components with HP ArcSight .......................................................................... 11
Cloud Service Automation 3.1 .............................................................................................................................................. 12
Matrix Operating Environment ............................................................................................................................................. 13
Server Automation .................................................................................................................................................................. 15
VMware ESXi 5 Host ............................................................................................................................................................... 15
Networking ............................................................................................................................................................................... 21
HP TippingPoint Security Management System (SMS) Appliance ................................................................................ 22
Protecting CloudSystem Enterprise Services with HP ArcSight ........................................................................................ 25
HP LAMP solution .................................................................................................................................................................... 25
Working with events ................................................................................................................................................................... 27
Searching the HP ArcSight Logger ...................................................................................................................................... 27
HP ArcSight ESM Viewing Events with Active Channels ............................................................................................... 29
Zones ......................................................................................................................................................................................... 31
Queries ...................................................................................................................................................................................... 31
Rules .......................................................................................................................................................................................... 34
Cloud Security Alliance ............................................................................................................................................................... 35
Summary ....................................................................................................................................................................................... 36
Zobrazit stránku 0
1 2 3 4 5 6 ... 38 39

Shrnutí obsahu

Strany 1 - HP CloudSystem Enterprise

Technical white paper HP CloudSystem Enterprise Integrating security with HP ArcSight Table of contents Executive summary ...

Strany 2

Technical white paper 10 Forwarding events to HP ArcSight ESM The HP ArcSight Logger can be used to aggregate events and forward specific events to

Strany 3 - Executive summary

Technical white paper 11 We can also forward events from specific devices or device groups. In our example in Figure 10, we have created a forwarde

Strany 4 - HP ArcSight overview

Technical white paper 12 Cloud Service Automation 3.1 Monitoring of events that occur in the core applications that comprise HP CloudSystem Enterpri

Strany 5 - HP ArcSight Connectors

Technical white paper 13 The events captured from the log4j application logs will be sent to the HP ArcSight Logger and then select events can be c

Strany 6 - Typical deployment scenarios

Technical white paper 14 HP Virtual Connect To enable HP Virtual Connect (VC) to be monitored and viewed in HP ArcSight Logger and HP ArcSight ESM,

Strany 7

Technical white paper 15 Figure 14. Enabling Virtual Connect Remote System Logging • Select “Test”. By doing so, a test message is sent to the Lo

Strany 8

Technical white paper 16 Figure 15. Setting the ESXi Syslog.global.logHost variable • Select “OK”. • Select “Security Profile” under the “Softwa

Strany 9 - Grouping devices

Technical white paper 17 – In the “Firewall Properties” window, scroll down the list until you see “syslog” and select the check box to enable it

Strany 10 - Technical white paper

Technical white paper 18 – Optionally, you can select the “Firewall…” button, select the “Only allow connections from the following networks” radio

Strany 11

Technical white paper 19 Figure 19. Selection of “VMware Web Services” • Select the “Details” tab and select “Copy to File…” – Select “Next >

Strany 12 - Cloud Service Automation 3.1

Technical white paper Appendix A: ASLinuxAudit.props ...

Strany 13 - Matrix Operating Environment

Technical white paper 20 Figure 20. Selection of “VMware Web Services” Connector • Select “true” for the “ValidateCert” option, then select “Next

Strany 14

Technical white paper 21 Figure 21. Example of completed Connector VMware Web Services device details – NOTE: If you get an information dialog bo

Strany 15

Technical white paper 22 HP TippingPoint Security Management System (SMS) Appliance The TippingPoint product has two types of devices, sensors and S

Strany 16 - • Select “OK”

Technical white paper 23 • Select “Add” on the “Enter the device details” window and enter the following: – Host – Host name or IP address of the

Strany 17

Technical white paper 24 • Log into the HP TippingPoint SMS and navigate to “Admin > Server Properties > Syslog” – Select the “New…” button

Strany 18

Technical white paper 25 Protecting CloudSystem Enterprise Services with HP ArcSight In addition to protecting the HP CloudSystem Enterprise core c

Strany 19

Technical white paper 26 The zip file is then imported into Server Automation. Add a Post-Install script as seen in Figure 27 to run the silent inst

Strany 20

Technical white paper 27 Figure 28. Policy Items Including the ArcSightSecurityPackages policy into the MariaDB-RHEL6 and ApacheWordPress-RHEL6 po

Strany 21

Technical white paper 28 log4j.appender.cef1=com.hp.esp.arcsight.cef.appender.Log4jAppender log4j.appender.cef1.deviceVendor=HP log4j.appender.cef

Strany 22

Technical white paper 29 HP ArcSight ESM – Viewing Events with Active Channels Events can be viewed in the ESM using an Active Channel. To view eve

Strany 23

Technical white paper 3 Executive summary Organizations are faced with threats that could disrupt operations and critical IT services. HP CloudSyst

Strany 24

Technical white paper 30 Figure 33. View of Failed Logons with additional fields Click on the event to view the event details. Looking at the detai

Strany 25

Technical white paper 31 Zones High value assets can be grouped into Zones. A Zone is based on a range of IP Addresses which can be used as a filte

Strany 26 - Figure 27. Policy Properties

Technical white paper 32 Figure 37. ESM Query Failed Logon – General In the Fields tab we can select which event fields we want to return and displ

Strany 27 - Working with events

Technical white paper 33 Next we’ll create a query viewer that will be used to execute our Failed Logon Query. We’ve named this Query Viewer “Faile

Strany 28

Technical white paper 34 Rules Rules are used to trigger an Action when a specific event or event(s) occur. Keeping with our Failed Logon example we

Strany 29

Technical white paper 35 Cloud Security Alliance The Cloud Security Alliance is a not-for-profit-organization that provides guidance, education, an

Strany 30

Technical white paper 36 Table 1. Security controls Control Number Description HP ArcSight Information Security – User Access Reviews IS-10 All leve

Strany 31

Technical white paper 37 # What would you like to do? # # Please select one of the following options : # # 0 - Add a Connector(addconnector) #

Strany 32

Technical white paper 38 # ========================================================= # Panel 'connectordetails' # ========================

Strany 33

Technical white paper For more information Learn more at hpenterprisesecurity.com/products To read more about CloudSystem Enterprise go to hp.com/

Strany 34

Technical white paper 4 comprehensive service automation solution. Cloud Service Automation (CSA) can leverage CloudSystem Matrix infrastructure ser

Strany 35

Technical white paper 5 Key Benefits • A cost-effective solution for all your regulatory compliance needs • Automated log collection and archivin

Strany 36 - Summary

Technical white paper 6 Typical deployment scenarios Security and log event information is captured at the host and application level. Events can be

Strany 37

Technical white paper 7 Sending events to HP ArcSight Logger using Connectors HP ArcSight Connectors can be installed on CloudSystem Enterprise hos

Strany 38

Technical white paper 8 Sending events to HP ArcSight ESM using Connectors The HP ArcSight Connectors can also send CEF formatted log data directly

Strany 39 - For more information

Technical white paper 9 Devices As systems connect to the HP ArcSight Logger, either through the UDP receiver or the SmartMessage receiver, they wi

Komentáře k této Příručce

Žádné komentáře