Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 

Configuring a Honeycomb Lexicon FIM Log Source in JSA

 

JSA automatically discovers and creates a log source for file integrity events that are forwarded from the Honeycomb Lexicon File Integrity Monitor.

The following procedure is optional:

  1. Log in to JSA.
  2. Click the Admin tab.
  3. In the navigation menu, click Data Sources.
  4. Click the Log Sources icon.
  5. Click Add.
  6. In the Log Source Name field, type a name for your log source.
  7. In the Log Source Description field, type a description for your log source.
  8. From the Log Source Type list, select Honeycomb Lexicon File Integrity Monitor.
  9. From the Protocol Configuration list, select Syslog.
  10. Configure the following values:

    Table 1: Syslog Protocol Parameters

    Parameter

    Description

    Log Source Identifier

    Type the IP address or host name for the log source as an identifier for events from your Honeycomb Lexicon FIM installation.

    The Log Source Identifier must be unique value.

    Enabled

    Select this check box to enable the log source. By default, the check box is selected.

    Credibility

    From the list, select the Credibility of the log source. The range is 0 - 10.

    The credibility indicates the integrity of an event or offense as determined by the credibility rating from the source devices. Credibility increases if multiple sources report the same event. The default is 5.

    Target Event Collector

    From the list, select the Target Event Collector to use as the target for the log source.

    Coalescing Events

    Select this check box to enable the log source to coalesce (bundle) events.

    By default, automatically discovered log sources inherit the value of the Coalescing Events list from the System Settings in JSA. When you create a log source or edit an existing configuration, you can override the default value by configuring this option for each log source.

    Incoming Event Payload

    From the list, select the incoming payload encoder for parsing and storing the logs.

    Store Event Payload

    Select this check box to enable the log source to store event payload information.

    By default, automatically discovered log sources inherit the value of the Store Event Payload list from the System Settings in JSA. When you create a log source or edit an existing configuration, you can override the default value by configuring this option for each log source.

  11. Click Save.
  12. On the Admin tab, click Deploy Changes.

    Honeycomb Lexicon File Integrity Monitor events that are forwarded to JSA are displayed on the Log Activity tab.