Imperva SecureSphere
The JSA DSM for Imperva SecureSphere collects all relevant syslog events from your Imperva SecureSphere devices.
The following table lists the specifications for the Imperva SecureSphere DSM:
Specification |
Value |
---|---|
Manufacturer |
Imperva |
DSM name |
SecureSphere |
RPM file name |
DSM- Imperva Secure sphere- JSA-version-Build_number .noarch. rpm |
Supported versions |
v6.2 and v7.x to v13 Release Enterprise Edition (syslog) v9.5 to v13 (LEEF) |
Event format |
syslog LEEF |
JSA recorded event types |
Firewall policy events |
Automatically discovered? |
Yes |
Includes identity? |
Yes |
Includes custom properties? |
No |
More information |
Imperva website (http://www.imperva.com) |
To send events from Imperva SecureSphere devices to JSA, complete the following steps:
If automatic updates are not enabled, download and install the most recent version of the Imperva SecureSphere DSM RPM from the Juniper Downloads onto your JSA Console.
For each instance of Imperva SecureSphere, configure the Imperva SecureSphere appliance to communicate with JSA. On your Imperva SecureSphere appliance, complete the following steps
Configure an alert action. See Configuring an Alert Action for Imperva SecureSphere .
Configure a system event action. See Configuring a System Event Action for Imperva SecureSphere.
If JSA does not automatically discover the Imperva SecureSphere log source, create a log source for each instance of Imperva SecureSphere on your network. Use the following table to define the Imperva SecureSphere-specific parameters:
Table 2: Imperva SecureSphere Log Source Parameters Parameter
Description
Log Source Type
Imperva SecureSphere
Protocol Configuration
Syslog