Configuring a Log Source for Sourcefire Intrusion Sensor in JSA
JSA automatically discovers and creates a log source for syslog events from Sourcefire Intrusion Sensor. However, you can manually create a log source for JSA to receive syslog events. The following procedure is optional.
- Log in to JSA.
- Click the Admin tab.
- On the navigation menu, click Data Sources.
- Click the Log Sources icon.
- Click Add
- In the Log Source Name field, type a name for your log source.
- In the Log Source Description field, type a description for your log source.
- From the Log Source Type list, select Snort Open Source IDS..
- From the Protocol Configuration list, select Syslog.
- Configure the remaining parameters.
- Click Save.
- On the Admin, click Deploy Changes.
You are now ready to configure the log source in JSA.