XYGATE Merged Audit Reference Manual

Table Of Contents
XYGATE Merged Audit
®
Reference Manual
Chapter 8. Maintaining the XMA Database
XYPRO Technology Corporation 146 Proprietary and Confidential
The Archive and Cleanup processes will check Filters with MOVER paragraphs with
the PRODUCT set to FILEMAINT. They will find the MOVER paragraph with an
ACTIONTYPE of RETAIN and check the value of the RETAIN_DAYS or
RETAIN_MONTHS keyword, and then process audit records in the XMA database that
match the data selection criteria for the Filter accordingly.
MOVERs ignore the FILEMAINT Filters. The ARCHIVE and CLEANUP processes only
read FILEMAINT Filters. Therefore, if you want to create alerts for audit events that
you also wish to retain in the XMA database for extended periods of time, you must
create two MOVERs with the same selection criteria but different MOVER criteria and
different ACTION paragraphs.
RETAIN Parameters
Filters that are used to configure the selective Archive or Cleanup must be configured
with:
A MOVER paragraph with the PRODUCT = FILEMAINT
An ACTION paragraph with:
1. ACTIONTYPE = RETAIN and,
2. Either the RETAIN_MONTHS or RETAIN_DAYS keyword.
FILEMAINT The FILEMAINT keyword is used to implement selective Archive or
Cleanup. A Filter with a MOVER paragraph with
PRODUCT = FILEMAINT must also include an ACTION paragraph
with an ACTIONTTYPE of RETAIN.
RETAIN The ACTIONTYPE that defines the length of time that audit records
matching the data selection criteria for the Filter will be retained.
RETAIN_DAYS The number of days that audit records matching the Filter’s
selection criteria will be retained in the XMA database before being
removed by either ARCHIVE or CLEANUP.
Enter day(s) as a number between 1 and 5500 (15 years) or –1,
which means never remove.”
RETAIN_MONTHS The number of months that audit records matching the Filter’s
selection criteria will be retained in the XMA database before being
removed by either ARCHIVE or CLEANUP.
Enter the month(s) as a number between 1 and 180 (15 years) or
1, which means never remove.
You cannot add any other MOVER paragraphs to a Filter with
PRODUCT = FILEMAINT.
The RETAIN_DAYS and RETAIN_MONTHS keywords are mutually exclusive. You
can only use one or the other, not both in the same Filter.