Syslog - Epic Hyperspace CEF
Device Details
Vendor | Epic Systems |
---|---|
Device Type | Electronic Healthcare Records |
Supported Model Name/Number | N/A |
Supported Software Version(s) | Epic 2015-2017 |
Collection Method | Syslog |
Configurable Log Output? | Yes |
Log Source Type | Syslog ā Epic Hyperspace CEF |
Log Processing Policy | LogRhythm Default |
Exceptions | N/A |
Additional Information | N/A |
Prerequisites
Two Epic Interconnect Custom Message Queues must be setup prior to syslog configuration. See Epic User Auditing Guide for complete steps. (Page 48, Epic User Auditing Guide, Epic 2017)
Device Configuration Checklist
- In the Epic Hyperspace user interface, go to Epic System Definitions, Security, Auditing Options, SIEM Syslog Settings, and SIEM Syslog Configuration Options. Then complete the following:
- Enter SIEM Host (LogRhythm System Monitor) IP or Hostname.
- Enter SIEM Port (Usually port 514 for Syslog).
- Set Logging Format to CEF (Common Event Format).
- Set Syslog Ending Character to New Line ā\nā.
- Set Check Application Layer Response to Disabled.
- Choose how to send record pointers to the SIEM.
- Hash. SHA-256 Hash Value ā Recommended, Default
- Keep. Record Pointer as it appears in Epic
- Delete. Record Pointers not sent
Record pointers include patient, hospital account and provider records. Hashing or not passing through record pointers can be used as an additional layer of protection for potentially confidential record pointers. It is recommended to use the hash option to have visibility into the Epic environment and retain confidentiality. - (Optional) Set which auditing events are sent to LogRhythm in case of too much traffic.
- Edit Events List.
- To disable undesired events, press T.
- To quit, press Q.
- Return to the SIEM Syslog Settings menu.
- Select SIEM Syslog and set to Enabled.
Currently Supported Events
Type |
---|
STARTUP |
LOGIN |
FAILEDLOGIN |
E_FAILEDPASSWORDCHANGE |
E_ADMINPASSWORDCHANGE |
E_SELFPASSWORDCHANGE |
CONTEXTCHANGE |
SECURE |
SWITCHUSER |
AUTHENTICATION |
NATIVE2FACTOR_BYPASS |
PHI_CLIENT_FILE |
EVENT_LOGGING_ENABLED |
EVENT_LOGGING_DISABLED |
EW_LOGIN |
HKU_LOGIN |
HKU_FAILED_LOGIN |
CTO_LOGIN |
CTO_FAILED_LOGIN |
ROVER_LOGIN |
ROVER_FAILED_LOGIN |
E_HIDDEN_SOURCE_ACCESS_GRANTED |
E_HIDDEN_SOURCE_ACCESS_DENIED |
ARCHLOG |
PUL_SEARCH_AUDIT |
AC_BREAK_THE_GLASS_ACCESS |
AC_BREAK_THE_GLASS_FAILED_ACCESS |
AC_BREAK_THE_GLASS_INAPPROPRIATE_ATTEMPT |
MASKED_DATA_DISPLAY |
MASKED_DATA_PRINTING |