{"id":821,"date":"2020-06-29T16:50:35","date_gmt":"2020-06-29T20:50:35","guid":{"rendered":"https:\/\/increasec.com\/?p=821"},"modified":"2020-08-07T17:33:53","modified_gmt":"2020-08-07T21:33:53","slug":"alien-vault-siem","status":"publish","type":"post","link":"https:\/\/increasec.com\/?p=821","title":{"rendered":"Alien Vault SIEM"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Agents:   Agents need to be deployed individually as a unique encryption string is generated per PC.<br>Environment, Detection, Agents Tab, Agent Control, Add Agent<br>search or choose from list<br>if a pc is not present add its subnet to scans<br>Agent name does NOT need to be DNS name<br>etc etc ok<br>Actions column, choose Automatic Agent Deployment for Windows<br>Enter an administrator User\/pw<br>click Deploy<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Plugins:<br>Environment, Assets,<br>find the asset and click the magnifying glass on right, Plugins tab, edit Plugins, Fortinet, FortiGate etc<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Scans:<br>Environment, Vulnerabilities, Scan Jobs<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Email setup:<br>Configuration, Deployment, click the Magnifying Glass icon, General Configuration, Mail Relay = Yes.   <br>smtp relay =   <strong>smtp<\/strong>.<strong>office365<\/strong>.com<br>user =  steve@company.com<br>pw =   whatever<br>tcp port =  587<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Alerts from Alarms:<br>Config, Threat Intel, Actions, New<br>Name = Email Alert  (or Something descriptive)<br>Description = name, date, description of change<br>Type = Send an Email message<br>From = must be a valid user<br>To = probably should be a valid user<br>Subject = AlienVault Alert<br>Body = https:\/\/lisiem.company.com,  click some fields from top of page<br>Append Event fields = Yes<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Now we use the Policy Menu to add this action as a policy.<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>From the&nbsp;Threat Intelligence&nbsp;menu, choose&nbsp;Policy.<\/li><li>Under \u201cPolicies for events generated in server,\u201d click&nbsp;New.<\/li><li>Top of page, near Policy Rule Name, enter a unique name like &#8220;Send Email Alerts&#8221;<\/li><li>under Policy Conditions, checkmark Directive Events<\/li><li>Under Consequences, Actions, click No Action<\/li><li>In bottom pane under Available Actions, click the + next to Email Alert  (or whatever you called it in the previous step)<\/li><li>Near bottom of the page click Update Policy<\/li><li>under Policies for events generated in server, click Reload Policies<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Enable Syslogs from Ubiquiti<br>Settings Gear bottom left, Network Settings, Advanced, <br>Remote Logging, Enable Syslog = Yes<br>Syslog Server = DNS name of SIEM server<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Alternate:   DeepBlueCli<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Agents: Agents need to be deployed individually as a unique encryption string is generated per PC.Environment, Detection, Agents Tab, Agent Control, Add Agentsearch or choose from listif a pc is&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[112],"class_list":["post-821","post","type-post","status-publish","format-standard","hentry","category-uncategorised","tag-siem"],"_links":{"self":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/821","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=821"}],"version-history":[{"count":9,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/821\/revisions"}],"predecessor-version":[{"id":900,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/821\/revisions\/900"}],"wp:attachment":[{"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=821"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=821"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=821"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}