XYGATE Merged Audit Reference Manual

Table Of Contents
XYGATE Merged Audit
®
Reference Manual
Appendix G: Data Mapping
XYPRO Technology Corporation 266 Proprietary and Confidential
Special Processing for CLIM
The EMS MOVER parses messages from CLIMs differently as outlined in the following
table:
TABLE.COLUMN
AUDIT.OBJECTTYPE
SSID
AUDIT.OPERATION CLIM-ACCEPT-PUBKEY, CLIM-OPEN-SESSION,
CLIM-CLOSE-SESSION, CLIM-DISCONNECT
AUDIT.MESSAGECODE PORT
AUDIT.TERMINAL
Process + Terminal
AUDIT.RULENAME CLIM name
SESSION.SESSIONID Processed + timestamp
SESSION.IPADDRV46 IP address
Special Processing for LISTNERs and TELNET
The EMS MOVER parses messages from LISTNER and TELNET differently as
outlined in the following table:
LISTNER CONNECT TELNET CONNECT and
DISCONNECT
RECORDGMT
RECORDLCT
SESSION-CONNECT-TIMESTAMP
OBJECTTYPE SSID SSID
OBJECTNAME TCP/IP Process Name:PORT TCP/IP Process Name:PORT
OPERATION LISTNER-CONNECT TELNET-CONNECT
- or -
TELNET-DISCONNECT
MESSAGECODE LOCAL PORT LOCAL PORT
TERMINAL
See EMS Note 3 (page 262).
PROCESS+TERM
RULENAME SERVICE-NAME SERVICE-NAME
Special Processing for OSS SU (substitute user) Command
The EMS MOVER parses messages from SU commands differently as outlined in the
following table:
OPERATION AUTHENTICATE
MESSAGEID ZEMS_TKN_EVENTNUMBER
Will equal 8 for a Failure.
Will equal 11 for a Success.