Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

VMware VShield

 

The JSA DSM for VMware vShield can collect event logs from your VMware vShield servers.

The following table identifies the specifications for the VMware vShield Server DSM:

Table 1: VMware VShield DSM Specifications

Specification

Value

Manufacturer

VMware

DSM

vShield

RPM file name

DSM-VMwarevShield-build_number.noarch.rpm

Supported versions

 

Protocol

Syslog

JSA recorded events

All events

Automatically discovered

Yes

Includes identity

No

More information

http://www.vmware.com/

VMware VShield DSM Integration Process

You can integrate VMware vShield DSM with JSA.

Use the following procedures:

  1. If automatic updates are not enabled, download and install the most recent version of the VMware vShield RPM on your JSA console.

  2. For each instance of VMware vShield, configure your VMware vShield system to enable communication with JSA. This procedure must be completed for each instance of VMware vShield.

  3. If JSA does not automatically discover the log source, for each VMware vShield server that you want to integrate, create a log source on the JSA console.

Related Tasks

Configuring your VMware vShield system for communication with JSATo collect all audit logs and system events from VMware vShield, you must configure the vShield Manager. When you configure VMware vShield, you must specify JSA as the syslog server.

Configuring a VMware vShield log source in JSATo collect VMware vShield events, configure a log source in JSA.

Configuring Your VMware VShield System for Communication with JSA

To collect all audit logs and system events from VMware vShield, you must configure the vShield Manager. When you configure VMware vShield, you must specify JSA as the syslog server.

  1. Access your vShield Manager inventory pane.
  2. Click Settings & Reports.
  3. Click Configuration >General.
  4. Click Edit next to the Syslog Server option.
  5. Type the IP address of your JSA console.
  6. Optional: Type the port for your JSA console. If you do not specify a port, the default UDP port for the IP address/host name of your JSA console is used.
  7. Click OK.

Configuring a VMware VShield Log Source in JSA

To collect VMware vShield events, configure a log source in JSA.

  1. Log in to JSA.
  2. Click the Admin tab.
  3. In the navigation menu, click Data Sources.
  4. Click the Log Sources icon.
  5. Click Add.
  6. From the Log Source Type list, select VMware vShield.
  7. From the Protocol Configuration list, select Syslog.
  8. Configure the remaining parameters.
  9. Click Save.
  10. On the Admin tab, click Deploy Changes.