XYGATE Merged Audit Reference Manual

Table Of Contents
XYGATE Merged Audit
®
Reference Manual
Chapter 3. Configuring Filters and the FILTERS File
XYPRO Technology Corporation 77 Proprietary and Confidential
Why choose IPALERT?
IPALERT actions send the audit data to the SIEM via UDP. IPALERT is required by
some appliances such as the HP CLW appliance, which currently accepts only UDP
syslog input.
With the IPALERT action, each individual MOVER opens the outgoing PORT and
sends the individual audit record that it is processing and then closes the PORT.
Audit events cannot be easily resent.
3.7.1 Configuring Filters to Implement a SIEM
There are two sample IPALERT Filters and two sample SYSLOGQ Filters in the
FILTSAMP file in the XYGATEMA subvolume. One Filter of each type will send audit
information gathered by all MOVERs except EMS. The other sends only those
gathered by EMS MOVERs.
The Filters for EMS events have been separated because EMS logs contain many
types of messages and you may wish to send only selected security-related EMS
messages to the SIEM.
To transmit only selected events, you will want to add one or more Data Selection
paragraphs to the appropriate "EMS-ONLY" Filter before changing its status to
ACTIVE. Refer to section 3.3.5, “Step 5. Define the Filters Data Selection Criteria” on
page 48 for more information.
For either type of SYSLOG Filter, you must define information about the SIEM:
IPALERT_ADDRESS The IP address of the target SIEM appliance.
IPALERT_PORT This is the receiving PORT on the appliance.
IPALERT_PREFIX This is a syslog protocol prefix, which may or may not be
required by your SIEM.
And information about the NonStop server:
IPALERT_PROCESS You must enter the TCP/IP process on the NonStop server
that will send the message.
An Optional Keyword:
IPALERT_SET_ALERTED The keyword IPALERT_SET_ALERTED allows you to
specify whether or not to set the ALERTED flag to a value
other than N. This option only applies to the filter where it
is specified. If you are using EVALUATE_MSG and
another alert type is generated, the flag will be set to A.