XYGATE Merged Audit Reference Manual

Table Of Contents
XYGATE Merged Audit
®
Reference Manual
Chapter 3. Configuring Filters and the FILTERS File
XYPRO Technology Corporation 78 Proprietary and Confidential
The ALERTSTRING keyword determines what information within an audit record will
be sent to the SIEM. The default Filters are designed to send every column of every
XYGATEMA data table to the SIEM in a preset order.
Important! Do not change the order or the tokens defined in these Filters. SIEMS are
programmed to parse these columns into their databases in the order defined in the
default FILTERS file.
3.7.2 Configuring Filters to Transmit Data via UDP
The Filters for IPALERT actions in the FILTSAMP file for transmitting data via UDP
are:
$UDP-ALL-EVENTS-EXCEPT-EMS
$UDP-EMS-EVENTS-ONLY
1.
Enter the IPALERT_PORT.
It is usually 514, but can be any number. Check with your SIEM administrator.
IPALERT_PORT 514
2.
Enter the IPALERT_PREFIX.
This keyword is optional. If present, it can be string text or a standard syslog prefix.
Check with your SIEM administrator to see if a certain prefix is required.
3. Enter the name of the NonStop server TCP/IP process that will send the syslog
message.
IPALERT_PROCESS $ZCT0
4.
Enter the SIEM’s IP address.
IPALERT_ADDRESS 10.1.1.27
5.
Test the parameters via the Movers Management Menu, option 16: (page 101)
XYGATEMA will send a test message to the SIEM to verify that parameters are
correct and that there are no firewall issues.
6. Change the status of all UDP filters to ACTIVE.
XYGATEMA will start sending audit information to the SIEM.