12.07.2015 Views

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

13Managing <strong>McAfee</strong> DLP systemsAdding servers to <strong>McAfee</strong> DLP systems11 Open a web browser and enter the address of the <strong>McAfee</strong> DLP appliance in the address bar.12 Return the Windows clock setting to the correct time zone.Reset time manuallyReset time manually by stopping and restarting NTP services.Stop and restart the NTP daemon to manually reset the time.Task1 Log on as root to the <strong>McAfee</strong> DLP appliance.2 Stop the NTP daemon.# service ntpd stop# chkconfig ‐‐level 2345 ntpd off3 Restart the NTP daemon.# service ntpd start# chkconfig ‐‐level 2345 ntpd onThe service command will control the service while the system is running; the chkconfigcommands will control what happens at boot time.Syslog server message structureSyslog servers are automatically recognized if they reside on the same network as DLP devices; nospecial connection is needed. If a syslog server is installed on the network, DLP automatically sendsmessages about significant events in the following format.The health of the DLP appliances, as well as the rule hits, are automatically transferred to the syslogserver.Table 13-3 Syslog server message definitionsMessage fieldDateHost nameComponentFormatDevice vendorDevice productDevice versionRuleSeverity #PolicyPolicy labelMatch countMatch count labelSource IPDestination IPSource PortDefinitionDate the event was loggedName or IP address of the machine that logged the eventComponent or process that generated an alertFormat version of the syslog outputVendor nameManager, Monitor, Discover, Prevent or Endpoint<strong>Product</strong> versionSearch ruleCritical, High , Medium, Low, InformationalPolicy nameType of objectMatches foundType of objectSource IP addressDestination IP addressSource port260 <strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!