- Community Home
- >
- Networking
- >
- IMC
- >
- IMC correlated alarms (integration with siem)
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-20-2020 02:34 AM
01-20-2020 02:34 AM
IMC correlated alarms (integration with siem)
We are looking for integration HPe IMC with LogRhythm, the purpose of this integration is to see IMC correlated alarms in LogRhythm SIEM.
I find the path where we can find all IMC logs C:\Program Files\iMC\server\conf\log\, but here I can‘t find any alert logs. In log file imcnetresdmxxx.xx.xx I can find information about network device reboot or power on, but the problem is that here we get information only then when device is up after power off.
I am looking for information where I can find logs which can show information when network device started to be not reachable. Thanks in advance.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-20-2020 04:49 AM
01-20-2020 04:49 AM
Re: IMC correlated alarms (integration with siem)
Hello,
I would not recommend trying to correlate iMC Alarms with a SIEM using the logfiles on the iMC system. These logs are primarily intended for use by Support and Engineering to troubleshoot issues.
As far as I can see, LogRhythm supports SNMP as an event source. Hence you should be able to set up iMC's Alarm Forwarding feature to forward all Alarms as SNMPv1 Traps to the LogRhythm software. That can be configured under Alarm > Alarm Settings > Alarm Notification > Add Alarm Forwarding rule.
Here is an example for you, where we forward only the 'device does not respond to poll packets' alarm:
Hope that helps.
Justin
Working @ HPE