DSM Editor
Perform the following steps in the DSM editor:
Qualys FIM JSON
In the Configuration tab, check if the following fields are set with the mentioned values:
- Select Log Source Type ( Qualys FIM JSON ) > Configuration > Log Source Autodetection Configuration.
- Enable Log Source Autodetection.
- Click Show Advanced Options and set the following as mentioned:
-
Minimum Successful Events for Autodetection: 2
-
Minimum Success Rate for Autodetection: 100
-
Attempted Parse Limit: The default value can be retained
-
Consecutive Failed Parse Limit: The default value can be retained
-
Qualys FIM INCIDENTS
In the Configuration tab, check if the following fields are set with the following mentioned values:
- Select Log Source Type ( Qualys FIM INCIDENT) > Configuration > Log Source Autodetection Configuration.
- Enable Log Source Autodetection.
- Click Show Advanced Options, and set the following as mentioned:
- Minimum Successful Events for Autodetection: 1
- Minimum Success Rate for Autodetection: 100
- Attempted Parse Limit: The default value can be retained
- Consecutive Failed Parse Limit: The default value can be retained
Log Source Event Mapping
Qualys FIM JSON
Search results are displayed based on the QID or name entered.
- Go to Admin > DSM Editor.
- In Select Log Source Type, search for Qualys FIM JSON.
- Click Select.
-
Go to the Event Mappings tab from the Qualys FIM JSON screen.
-
You can view mapping for FIM_EVENTS, FIM_IGNORED_EVENTS, and FIM _INCIDENT_EVENTS.
You must create a new one if you do not see mapping for FIM_EVENTS, FIM_IGNORED_EVENTS, and FIM _INCIDENT_EVENTS.
Use the following steps to create new mappings:
- Click the Choose QID link.
- High-LevelCategory: Any
- Low-Level Category: Any
- Log Source Type: Any
- QID/Name: In this text box, the user must search for Qualys FIM and click Search.
-
Click the + icon to add a new mapping.
The Create a new Event Mapping pop-up is displayed.
- Set Event ID as FIM_EVENTS, FIM_IGNORED_EVENTS and FIM_INCIDENT_EVENTS (without quotes).
- Set Category as FIM_EVENTS.
- Set FIM_INCIDENT_EVENTS (without quotes).
-
Choose Qualys FIM Events/Qualys FIM Ignored Events/Qualys FIM Incidents based on your requirements.
-
Click OK.
Create a new Event Mapping window is displayed.
-
Click Create.
The Event Mappings window is displayed.
You can verify the new event mapping created.
-
Click Save and close the window.
Qualys FIM INCIDENTS
- Go to Admin > DSM Editor.
- In Select Log Source Type, search for Qualys FIM INCIDENT.
- Click Select.
-
Go to the Event Mappings tab from the Qualys FIM INCIDENTS screen.
You can view mapping for FIM _INCIDENT_EVENTS.
You must create new mappings if you do not see a mapping for FIM_INCIDENT_EVENTS.
-
Click the + icon to add a new mapping.
The Create a new Event Mapping pop-up is displayed.
-
Set Event ID as FIM_INCIDENT_EVENTS (without quotes)
-
Set Category as FIM_INCIDENT_EVENTS (without quotes).
-
Click the Choose QID link
- High-LevelCategory: Any
- Low-Level Category: Any
- Log Source Type: Any
- QID/Name: In this text box, the user must search for Qualys FIM and click Search.
Search results are displayed based on the QID/Name entered.
-
Choose the Qualys FIM INCIDENTS option.
-
Click OK.
This takes you back to Create a new Event Mapping window.
-
Click Create. This takes you back to the Event Mappings window.
You can verify the newly created Event Mapping.
-
Click Save and close the window.