XYGATE Merged Audit Reference Manual

Table Of Contents
XYGATE Merged Audit
®
Reference Manual
Chapter 3. Configuring Filters and the FILTERS File
XYPRO Technology Corporation 76 Proprietary and Confidential
3.6.2 Step 2. Submit an INFO PROCESS
Then go into SCF and do an INFO PROCESS on the process name:
\NSKIT06 $DATA08.XYPRO 1>scf
SCF - T9082H01 - (04DEC06) (15NOV06) - 05/21/2008 09:48:22 System \NSKIT06
(C) 1986 Tandem (C) 2006 Hewlett Packard Development Company, L.P.
(Invoking \NSKIT06.$DATA08.XYPRO.SCFCSTM)
1-> info process $ztn5,detail
TELSERV Detailed Info PROCESS \NSKIT06.$ZTN5
PCPU................... 1 BCPU................... 0
PPIN................... 189 BPIN................... 725
TACL................... ON Transport Process..... $ZTC5 ?-
*Menu................... ON Transport Type......... TCP/IP
*Timeout Value.......... N/A Port................... 23
*Banner Timeout Value... N/A Total Services......... 2
*Max Terminals.......... 512 Total Terminals........ 8
Program................ \NSKIT06.$SYSTEM.SYS01.TELSERV
*CPU List............... 0 ,1 ,2 ,3 ,4 ,5 ,6 ,7 ,8 ,9 ,10 ,11 ,12 ,13 ,14 ,15
*DROPCR................. ON
The transport process name is the process name that you should enter as the:
IPALERT_IPPROCESS
MAIL_IPPROCESS
SNMP_IPPROCESS
3.7 Sending XMA Data to an Audit Logging Appliance
To configure XYGATEMA to send audit data to a Security Information and Event
Management (SIEM) appliance, requires configuring one or more Filters with the
ACTIONTYPE of either SYSLOGQ or IPALERT.
Why choose SYSLOGQ?
SYSLOGQ actions send the audit data to the SIEM via TCP/IP. This is the
recommended method of backing up NonStop server audit trail files to a centralized
server as required by PCI.
With SYSLOGQ, the MOVERs send the records to the queue, which is processed by
the SLSENDER Serverclass.
The SLSENDER opens the outgoing PORT on the NonStop server once, and
continuously processes its queue, sending messages to the port.
SYSLOGQ events can be “replayed” so if for any reason, the SIEM appliance
becomes unavailable, the audit records can be resent.