XYGATE Merged Audit Reference Manual

Table Of Contents
XYGATE Merged Audit
®
Reference Manual
Chapter 3. Configuring Filters and the FILTERS File
XYPRO Technology Corporation 80 Proprietary and Confidential
3.7.4 Troubleshooting Communication with SIEM Appliances
This section will help you troubleshoot the NonStop (XYGATEMA) side of the
communication with a SIEM appliance.
1. Verify that the IPALERT/SYSLOGQ Filter(s) Status is Active.
Review the FILTERS file either on the NonStop server using XMA_EDIT_FILTERS
(page 215) or with the XYGATE Configuration Manager GUI.
2. Verify that the Pathway and the MOVERs are running.
a. Do a status on the XYGATEMA pathway process name (default name is
$XMA).
2> status $xma
System \NODEA
Process Pri PFR %WT Userid Program file Hometerm
$XMA 0,209 145 001 255,255 $SYSTEM.SYSTEM.PATHMON $VHS
Swap File Name: $SYSTEM.#0
Current Extended Swap File Name: $SYSTEM.#0
$XMA B 1,68 145 001 255,255 $SYSTEM.SYSTEM.PATHMON $VHS
Swap File Name: $SYSTEM.#0
Current Extended Swap File Name: $SYSTEM.#0
b.
Check the status of the MOVERs with either Pathway Management Menu,
option 4: Quick Server Status (page 100), or via PATHCOM.
3. If you are sending data via TCP/IP, check the status of the SLSENDER server:
a. In the Pathway:
2 > pathcom $XMA
$Z94W: PATHCOM - T8344H01 - (01FEB10)
(C)1980 Tandem (C)2005-2008,2010 Hewlett Packard Development Company, L.P.
=status server slsender
SERVER #RUNNING ERROR INFO
SLSENDER 1
b.
In the Movers Management Menu, select option 21: Maintain Administrative
Servers (page 101).
4. Send a test IPALERT/SYSLOGQ message to the SIEM.
a. Use Movers Management Menu, option 16: Test basic Alerts (page 101).
b. Set the correct IP address and PORT for the SIEM and the NonStop TCP/IP
process that will send the message by selecting the appropriate number and
enter the values. When you have finished, select R: Run to initiate the test
message.