XYGATE Merged Audit Reference Manual

Table Of Contents
XYGATE Merged Audit
®
Reference Manual
Appendix G: Data Mapping
XYPRO Technology Corporation 267 Proprietary and Confidential
Special Processing for XYGATE SSH Encryption (SSH)
The EMS MOVER parses AUTHENTICATION messages from XSH as outlined in the
following table.
SUBJECTLOGIN
USERID from TEXT
TARGETLOGIN
USERID from TEXT
OBJECTNAME
SSID
OPERATION
AUTHENTICATE
MESSAGECODE
Port Number
AUDIT SESSION
IPADDRV46 IPADDRESS from TEXT
Special Processing for HP SSH Encryption (comForte
®
SSH)
The EMS MOVER parses AUTHENTICATION messages from XSH as outlined in the
following table:
SUBJECTLOGIN
USERID from TEXT
TARGETLOGIN
USERID from TEXT
OBJECTTYPE
SSID
OBJECTNAME
Target userid or SFTP file mask or Subsystem
OPERATION
AUTHENTICATE of SFTP command
RULENAME
Authentication method
MESSAGECODE
If OPERATION = LISTEN, then local Port
If OPERATION = FORWARD, then 'to' Port
AUDIT SESSION
IPADDRESS IPADDRV6 from TEXT
SESSIONID comForte SESSION-LOG-ID from TEXT