Hi Parinya
Would you please elaborate a little bit more. What do you mean by automating asset creation using VA data.
Hi nadeem,
Actually, it's nothing much. What I try to say is you don't have to create assets on SIEM manually. If you can connect SIEM with VA source then it allowed SIEM to retrive information from VA source. As a result, assets on SIEM will be automatically created for you with basic information such as their OS version and port opened for example. Then you can group those assets into lists and later use lists in correlation rule.
I just look at your question again and notice that you refer to vulnerability assessment data. So this may be not related. You should know about VA source already, I guess. Please ignore my messages.
Best regards,
Parinya
Message was edited by: parinya.ekparinya on 11/28/12 7:50:35 AM CSTThis is a very old post but i found responses useful.
I am working in a McAfee environment with Vulnerability Manager sending events/information to SIEM (ESM).
I am seeing lots of events i want to investigate further but the source IP is Vulnerability Manager/Scanner. I need to know the source of the issue, so i can troubleshoot/investigate. Does anyone know how i would find this???
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA