VMware VShield
The JSA DSM for VMware vShield collects event logs from VMware vShield servers.
The following table identifies the specifications for the VMware vShield Server DSM:
Specification |
Value |
---|---|
Manufacturer |
VMware |
DSM |
VMware vShield |
RPM file name |
DSM-VMwarevShield-JSA_version-build_number.noarch.rpm |
Protocol |
Syslog |
JSA recorded events |
All events |
Automatically discovered |
Yes |
Includes identity |
No |
More information |
VMware VShield DSM Integration Process
You can integrate VMware vShield DSM with JSA.
Use the following procedures:
-
If automatic updates are not enabled, download and install the most recent version of the VMware vShield RPM from the Juniper Downloads onto your JSA Console.
-
For each instance of VMware vShield, configure your VMware vShield system to enable communication with JSA. This procedure must be completed for each instance of VMware vShield.
-
If JSA does not automatically discover the log source, for each VMware vShield server that you want to integrate, create a log source on the JSA console.
Syslog Log Source Parameters for VMware vShield
If JSA does not automatically detect the log source, add a VMware vShield log source on the JSA Console by using the Syslog protocol.
When using the Syslog protocol, there are specific parameters that you must use.
The following table describes the parameters that require specific values to collect Syslog events from VMware vShield:
Parameter |
Value |
---|---|
Log Source Type |
VMware vShield DSM |
Protocol Configuration |
Syslog |
Log Source Identifier |
Type the IP address or hostname of the VMware device. The log source identifier must be unique value. |
Configuring Your VMware VShield System for Communication with JSA
To collect all audit logs and system events from VMware vShield, you must configure the vShield Manager. When you configure VMware vShield, you must specify JSA as the syslog server.
-
Access your vShield Manager inventory pane.
-
Click Settings & Reports.
-
Click Configuration >General.
-
Click Edit next to the Syslog Server option.
-
Type the IP address of your JSA console.
-
Optional: Type the port for your JSA console. If you do not specify a port, the default UDP port for the IP address/host name of your JSA console is used.
-
Click OK.