cancel
Showing results for 
Search instead for 
Did you mean: 
nsaman
Level 7
Report Inappropriate Content
Message 1 of 7

Configure SIEM Receiver onto another ESM

Hi All,


Currently, i have two separate site for SIEM. These are physical SIEM.

Site A:

ESM A

REC A

DBM A

ACE A

ADM A

Site B:

ESM B

REC B

DBM B

ACE B

ADM B

If site A was to go offline with the exception REC A. Can I use ESM B to have REC A connect to it without losing the data source that has been already configured while REC A was connected to ESM A?

If so, any help on the steps would be greatly appreciate

Regards,

NS

6 Replies

Re: Configure SIEM Receiver onto another ESM

It's possible to do it but it has to be manual process however you will loose log data during that process.

Maybe better option will be to setup redundant ESM.

Also there is an option to export/Import data sources

nsaman
Level 7
Report Inappropriate Content
Message 3 of 7

Re: Configure SIEM Receiver onto another ESM

We would like to keep things separate until a failover needs to be done to a different ESM.

would you happen to have the steps for moving a REC to a different ESM without losing data source?

Re: Configure SIEM Receiver onto another ESM

it should be as simple as adding receiver and then under the receiver properties there is sync button that will bring all of the data sources from the receiver to the ESM.

I never tried it but this is how it should work

nsaman
Level 7
Report Inappropriate Content
Message 5 of 7

Re: Configure SIEM Receiver onto another ESM

thanks, do you think we will need to have an export of the key and import it during the adding of the REC?

Highlighted

Re: Configure SIEM Receiver onto another ESM

HI,

This will be good but if by any reason you don't have it you can reset the key.

i'm not sure whether McAfee published the procedure to their external KB but it is standard linux command:

cat /etc/NitroGuard/factory-id_rsa.pub > /root/.ssh/authorized_keys2

Remember that the best will be first to test this so you can create procedure and include in in you DR process

nsaman
Level 7
Report Inappropriate Content
Message 7 of 7

Re: Configure SIEM Receiver onto another ESM

Thanks for all your help Alexander

More McAfee Tools to Help You
  • Subscription Service Notification (SNS)
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • eSupport: Policy Orchestrator
  • Community Help Hub

      New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

    • Find Forum FAQs
    • Learn How to Earn Badges
    • Ask for Help
    Go to Community Help

    Join the Community

      Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

    • Get helpful solutions from McAfee experts.
    • Stay connected to product conversations that matter to you.
    • Participate in product groups led by McAfee employees.
    Join the Community
    Join the Community