When you configure RSA SecurID Access Identity Router to send log data to USM Appliance, you can use the RSA SecurID Access Identity Router (IDR) plugin to translate raw log data into normalized events for analysis. The table below provides some basic information for the plugin:
|Data Source Name||Rsa-securid-idr|
|Data Source ID||1856|
Integrating RSA SecurID Access Identity Router
Before you configure the RSA SecurID IDR integration, you must have the IP Address of the USM Appliance Sensor.
To configure RSA SecurID IDR to send Syslog messages to USM Appliance
- Log in to RSA through Via Access using Super Administrator credentials.
- On the Via Access dashboard, click Platform > Auditing.
- On the Audit Logging screen, select Send to syslog in the Output Type field.
- In the Syslog Configuration section, enter the IP address of USM Appliance in the Server field.
- Set the following options:
- For Log user events, check Include authorization requests.
- For Log system events, check Include system error events.
- Click Save to save your changes, and return to the Dashboard.
- On the Dashboard, click Publish Changes.
- Log in to the USM Appliance shell.
Add the following rsyslog rule replacing 127.0.0.1 with the IP Address of the RSA device:
:fromhost, isequal, "127.0.0.1" /var/log/rsa-securid-idr.log
For plugin enablement information, see Enable Plugins.
Additional Resources and Troubleshooting
For troubleshooting, refer to the vendor documentation: