There are various methods by which you can extend Manager data to SIEM products. You can choose one based on the data involved and the type of the SIEM product.
The following methods are available:
Configure the Manager to push data to a SIEM product.
Configure a SIEM product to pull data from the Manager.
Query the Manager database for data.
The Manager itself provides multiple methods for backing up configuration and analysis data, including all policy, ignore rule, alert, and any associated packet information. These backup, archive, and export techniques, however, will only allow for the retrieval of the information through the Manager. A SIEM product must access the Manager through the standard system integration techniques.
The following data is available to SIEM products:
Alert information — When an attack is detected, an alert is raised and the configured response is executed. The alert information contains, where applicable, the specific attack details such as type, attacker and target addresses and ports, packet logs, and outcome.
Packet log information — A policy can include the requirement to log the packet information that is associated with an alert. This information is a record of the actual flow of traffic that triggered the attack and can be used for detailed packet analysis. This information must be pulled from the Manager database.
System Faults — Fault information contains the following details:
Admin domain where the fault is detected
Sensor name
Name of the fault
Type of fault
Fault owner
Fault level
Time of the fault
Fault source
Fault component
Severity
Description
Acknowledged flag
To view the list of all fault informational items, select → → → → → . Provide all the details and click Save. Then select Customized and click Edit. You can query faults from the iv_alarm table in the Manager database.
ACL Logs – Access Control Lists