The JSA DSM for FireEye accepts syslog events in Log Event Extended Format (LEEF) and Common Event Format (CEF).
This DSM applies to FireEye CMS, MPS, EX, AX, NX, FX, and HX appliances. JSA records all relevant notification alerts that are sent by FireEye appliances.
The following table identifies the specifications for the FireEye DSM.
Table 1: FireEye DSM Specifications
CMS, MPS, EX, AX, NX, FX, and HX
RPM file name
JSA recorded event types
All relevant events
FireEye website (www.fireeye.com)
To integrate FireEye with JSA, use the following procedures:
If automatic updates are not enabled, download and install the DSM Common and FireEye MPS RPM on your JSA Console.
For each instance of FireEye in your deployment, configure the FireEye system to forward events to JSA.
For each instance of FireEye, create an FireEye log source on the JSA Console.