XYGATE Merged Audit Reference Manual

Table Of Contents
XYGATE Merged Audit
®
Reference Manual
Chapter 3. Configuring Filters and the FILTERS File
XYPRO Technology Corporation 82 Proprietary and Confidential
The TFILTERS file contains a test version of the IPALERT Filter that, instead of
sending the contents of the columns to the log warehouse, sends the Element (Token)
Sequence numbers and Column titles so that the programmers can verify that the data
is being parsed into the correct columns in their database.
The Order and Contents of the Tokens Being Sent via IPALERT Filters
Numbered Elements from the IPALERT Filter GUI Report Manager
ALERTSTRING @0 (Not present)
ALERTSTRING @ E2 SESSION.RECORDSESSIONKEY (Not present) = empty
ALERTSTRING @ E3 SESSION.RECORDINSTALLKEY (Not present) = empty
ALERTSTRING @ E4 SESSION.SESSIONID Session ID
ALERTSTRING @ E5 SESSION.FOUNDSESSIONSTART Found Session Start
ALERTSTRING @ E6 SESSION.FOUNDSESSIONEND Found Session End
ALERTSTRING @ E7 SESSION.SESSIONNAME Session DNS Name
ALERTSTRING @ E8 SESSION.PROCESSTHREADID Process ID
ALERTSTRING @ E9 SESSION.PROCESSTHREADID2 Associated Process ID
ALERTSTRING @ E10 SESSION.CLIENTPROGRAM Client Program
ALERTSTRING @ E11
SESSION.ANCESTORPROCESSTHREADID
Ancestor Process ID
ALERTSTRING @ E12 SESSION.IPADDRESS IP
ALERTSTRING @ E13 SESSION.DNSNAME DNS Name
ALERTSTRING @ E14 SESSION.CLIENTCURRDIR Current Directory
ALERTSTRING @ E15 INSTALL.RECORDINSTALLKEY (Not present) = E3
ALERTSTRING @ (INSTALL.PRODUCTCODE)| Product Code
ALERTSTRING @ E17 INSTALL.IPADDREV46 IP
ALERTSTRING @ E18 INSTALL.SYSTEMNAME Product System
ALERTSTRING @ E19 INSTALL.LOCATION Product Location
ALERTSTRING @ E20 INSTALL.DNSNAME DNS Name
ALERTSTRING @0 (Not in excel)
ALERTSTRING @ |(AUDIT.RECORDGMT)| GMT Date Time
ALERTSTRING @ E23 AUDIT.GMTSEQNO GMT Seq Number
ALERTSTRING @ |(AUDIT.RECORDLCT)| Date Time
ALERTSTRING @ E25 AUDIT.RECORDAUDITKEY Audit Key
ALERTSTRING @ E26 AUDIT.RECORDSESSIONKEY (Not present) = E2
ALERTSTRING @ E27 AUDIT.SEQNO Seq Number
ALERTSTRING @ E28 AUDIT.OUTCOME Outcome
ALERTSTRING @ E29 AUDIT.WARNINGMODE Warning Mode
ALERTSTRING @ E30 AUDIT.TESTMODE Test Mode
ALERTSTRING @ E31 AUDIT.SEVERITY Severity
ALERTSTRING @ E32 AUDIT.ALERTED Alerted