Skip to main content
Skip table of contents

DoDI 8500.2 Deployment Guide – Configure the Compliance Package

LogRhythm requires that you configure some objects included in the DoDI 8500.2 Compliance Package.

Enable Intelligent Indexing

Intelligent Indexing allows Reports, Investigations, and Tails to keep the appropriate log data online in the Log Manager. Care must be taken when choosing which object to allow Intelligent Indexing as broad criteria can cause an exceptional amount of online data and overwhelm the Log Manager. For a list of Intelligent Indexing-capable objects and their recommended setting, see DoDI 8500.2—Reports.

Configure LogRhythm Data Management Settings

LogRhythm Compliance Packages rely on log data to be forwarded to various LogRhythm databases in order for the reports to properly populate and for proper archiving as dictated by the regulation. To ensure log data is being forwarded to the required databases, follow the data management steps outlined in Find More Information.

Classify Assets into Log Source Lists

Each DoDI 8500.2 compliance-relevant log source must be classified into one of the DoDI 8500.2 Log Source Lists. To see recommendations for which Technology Association may fall under which DoDI 8500.2 Log Source List Category, see DoDI 8500.2—Lists.

Activate Default Alarms

All alarms included in the DoDI 8500.2 Compliance Package are disabled by default. To meet compliance requirements, they must be enabled. For more information, see Enable or Disable Alarm Rules. In some cases, additional customization may be required to minimize false alarms.

Alarm NameRegulation Notes
DoDI 8500.2: Alarm On CompromiseBest Practice

Check Investigations

The following investigations should be contained in the Investigation tab.

Investigation NameIntelligent IndexingRegulation Notes
DoDI 8500.2: Network Connection SummaryNoMonitoring of compliance
DoDI 8500.2: Network Service SummaryNoMonitoring of compliance

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.