LogRhythm requires that you configure some objects included in the NEI Compliance Package. This section describes the steps you must perform.
Enable Intelligent Indexing
Intelligent Indexing allows Reports, Investigations, and Tails to keep the appropriate log data online in the Log Manager. Care must be taken when choosing which object to allow Intelligent Indexing as broad criteria can cause an exceptional amount of online data and overwhelm the Log Manager. For a list of Intelligent Indexing-capable objects and their recommended setting, see NEI 08-09 Rev 6—Reports.
Configure LogRhythm Data Management Settings
LogRhythm Compliance Packages rely on log data to be forwarded to various LogRhythm databases in order for the reports to properly populate and for proper archiving as dictated by the regulation. To ensure log data is being forwarded to the required databases, follow the data management steps outlined in Find More Information.
Classify Assets into Log Source Lists
Each NEI compliance relevant log source must be classified into one of the NEI Log Source Lists. To see recommendations for which Technology Association may fall under which NEI Log Source List Category, see NEI 08-09 Rev 6—Lists.
Activate Default Alarms
All alarms included in the NEI Compliance Package are disabled by default. To meet compliance requirements, they must be enabled. For more information, see Enable or Disable Alarm Rules. In some cases additional customization may be required to minimize false alarms.
|NEI: Alarm on Compromise||Best practice||30 min||Single Event|
|NEI: Alarm on Audit Log Write Failure||Indicates a system may be shutting down due to inability to audit||30 min||Single Event|
The following investigations should be contained in the Investigation tab.
|Investigations||Intelligent Indexing||Regulation Notes|
|NEI: Network Connection Summary||No||Monitoring of compliance|
|NEI: Network Service Summary||No||Monitoring of compliance|