Integrating Service Impact and Event Management
You can integrate with Service Impact and Event Management (SIEM) to collect event data into BMC TrueSight IT Data Analytics and analyze it.
The following steps are involved in collecting and analyzing event data:
- Configure a SIEM server.
- Create a data collector. For instructions about creating a data collector, see Creating data collectors for external configurations.
- Perform a search to analyze the events retrieved. For more information about performing a search, see Searching-the-data.
To configure a SIEM server
- Navigate to Settings > External Configurations.
- Select SIEM Configuration on the list on the top-left of your screen.
- Provide the following details:
(In the following table, the mandatory fields are marked with 🔵️).- 🔵️ Profile name: Provide a name to identify this external configuration.
- 🔵️ Cell name: Provide the name of the cell defined in SIEM (for example pncell_hostName) with which you want to connect and collect event data.
- 🔵️ Cell host: Provide the host name of the server where the cell is located.
- 🔵️ Cell port: Provide the port number of the server where the cell is located.
🔵️ Cell encryption key: Provide the cell's encryption key.
- Enable HA: Select this check box if you are operating in a High Availability environment. After selecting this check box, provide the host name and port number of the server where the secondary cell is located.
- Click Save.
Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*