McAfee Enterprise Security Manager Integration Guide
The McAfee® security information and event management (SIEM) solution brings event, threat, and risk data together to provide security intelligence, incident response, log management, and compliance reports. McAfee Enterprise Security Manager, at the core of McAfee's SIEM solution, delivers actionable intelligence and the real-time situational awareness required to identify, understand, and respond to threats, while the embedded compliance framework simplifies compliance.
McAfee Event Receiver is an add-on to Enterprise Security Manager. You can use it to collect log data from WatchGuard Fireboxes and provide the data to Enterprise Security Manager.
This document describes the steps to integrate Enterprise Security Manager and Event Receiver with your Firebox to enable log analysis on the SIEM system.
Platform and Software
The hardware and software used to complete the steps outlined in this document include:
- Firebox installed with Fireware v12.8.1
- McAfee Enterprise Security Manager v11.5.4 (Web Login)
- McAfee Event Receiver v11.5.4
Test Topology
This diagram shows the test topology for this integration. You can use either a Trusted or Optional interface.
Set Up the Firebox
Use these steps to set up a Firebox with a syslog server.
- Log in to Fireware Web UI at:
https://<your firebox IP address>:8080 - Select System > Logging > Syslog Server.
- Select the Send Log Messages to These Syslog Servers check box.
- To add a new syslog server, click Add.
The Syslog Server dialog box shows. - In the IP Address text box, type the IP address of the computer with the McAfee Event Receiver install.
- In the Port text box, type the port configured on McAfee Event Receiver to receive syslog data. The default setting is port 514.
- From the Log Format drop-down list, select Syslog.
- Keep other settings as the default values.
- Click OK.
The newly added server shows in the Syslog Server tab in Fireware Web UI.
- Click Save.
Set Up McAfee Enterprise Security Manager and Event Receiver
Use these steps to set up McAfee Enterprise Security Manager, add a McAfee Event Receiver, and add a data source.
- Log in to McAfee Enterprise Security Manager Web UI with the default user name NGCP and the default password security.4u.
- Configure any other initialization settings that you must set before you can add an Event Receiver.
In this guide, when the enable FIPS dialog box shows, we select No to remain in non-FIPS mode. For more information, see the McAfee Enterprise Security Manager documentation. - Click to expand the left navigation bar.
- Click More Settings.
The ESM Administrator App page opens.
- To begin to configure ESM, click Download.exe (Windows).
- Run the installer and install the program on your local computer.
- Click Launch.
- In the pop-up window, click Open McAfee ESM Administrator App.
- Select Confirm.
- Log in to the McAfee Enterprise Security Manager App with your user name and password.
The Configuration page opens.
- To add a McAfee Event Receiver, click .
The Add Device Wizard opens. - From the Select the Type of Device You Want to Install list, select McAfee Event Receiver.
- Click Next.
- In the Device Name text box, type a name.
- Click Next.
- In the Target IP Address or URL text box, type the IP address of the computer where you installed McAfee Event Receiver.
- Click Next.
- In the Enter Your New Password and Re-type Your New Password to Confirm text boxes, type and confirm a password for your device. For the added device, this password is the root password.
- Click Next.
The Your Device has Been Successfully Keyed page opens.
- Click Finish.
Your device shows on the Configuration page.
- Select the event receiver you added. In this example, the name is Event Receiver For WatchGuard .
- To add a data source, click .
The Add Data Source dialog box opens. - From the Data Source Vendor drop-down list, select WatchGuard Technologies.
- From the Data Format drop-down list, select Default.
- From the Data Retrieval drop-down list, select SYSLOG (Default).
- In the Name text box, type a name for the data source.
- In the IP Address text box, type the IP address of the data source. This is the IP address of the Firebox interface.
- From the Support Generic Syslogs drop-down list, select Parse as generic syslog.
- From the Generic Rule Assignment drop-down list, select User Defined 1.
- From the Time Zone drop-down list, select the time zone of the Firebox.
- Keep other settings as the default values.
- Click OK.
- Select Yes.
The Firebox is added to the Physical Display section. The Rollout window opens. - From the Device section, select WatchGuard Firebox.
- Click OK.
Test the Integration
To verify that your integration was successful, use a web browser to visit a website through the WatchGuard Firebox. Then verify that the Firebox sent log data to McAfee Enterprise Security Manager.
To see the data:
- Click to expand the left navigation bar.
- Select Investigation Tools > Dashboard.
- Verify that the expected log-related information shows.