XYGATE Merged Audit Reference Manual

Table Of Contents
XYGATE Merged Audit
®
Reference Manual
Chapter 8. Maintaining the XMA Database
XYPRO Technology Corporation 147 Proprietary and Confidential
Example 1 below will cause XHE audit records for FTP accesses to a database
containing cardholder data where the OPERATION is either GET or PUT to be
retained for 5 years. If you want to perform another ACTION such as sending an email
alert, you would need to add another Filter with the same selection criteria and
MOVER = XYGATEHE.
Example 1:
FILTERDEFBEGIN $RETAIN-DATABASE-GETS-PUTS
STATUS ACTIVE
MOVER_BEGIN
MOVER_SELECT_BEGIN
PRODUCT = FILEMAINT
MOVER_SELECT_END
MOVER_END
DATA_BEGIN
DATA_SELECT_BEGIN
FILTERTYPE STRINGFILTER
AUDIT.PRODUCTCODE = XYGATEHE
AUDIT.OPERATION LIKE "(GET|PUT)"
AUDIT.OBJECTTNAME LIKE "^\$DATA.*\.PRODDAT\..*"
DATA_SELECT_END
DATA_END
ACTIONCOLL_BEGIN
ACTION_BEGIN
ACTIONTYPE RETAIN
RETAIN_MONTHS 60 ! (5yr x 12mo)
ACTION_END
ACTIONCOLL_END
FILTERDEFEND
Example 2 will cause user maintenance audit records to be retained for 10 years. If
you want to retain the data forever,” use 1 (never delete):
Example 2:
FILTERDEFBEGIN $RETAIN-USER-MAINT-RECORDS
STATUS ACTIVE ! $RETAIN-USER-MAINT-RECORDS
MOVER_BEGIN
MOVER_SELECT_BEGIN
PRODUCT = FILEMAINT
MOVER_SELECT_END
MOVER_END
DATA_BEGIN
DATA_SELECT_BEGIN
FILTERTYPE STRINGFILTER
AUDIT.PRODUCTCODE = SAFEGUARD
AUDIT.OBEJECTTYPE LIKE "(USER|ALIAS)"
AUDIT.OPERATION LIKE "(CREATE|PURGE)"
AUDIT.MESSAGEID = 51
DATA_SELECT_END
DATA_SELECT_BEGIN
FILTERTYPE STRINGFILTER
AUDIT.OBJECTTYPE LIKE "(USER|ALIAS|REMOTEPASSWORD)"
AUDIT.OPERATION = CHANGE
AUDIT.MESSAGEID LIKE "^(54|55)$"
DATA_SELECT_END
DATA_END
ACTIONCOLL_BEGIN
ACTION_BEGIN