XYGATE Merged Audit Reference Manual

Table Of Contents
XYPRO Technology Corporation 303 Proprietary and Confidential
Glossary
This glossary provides explanations of the XMA components, including files and
macro, as well as the keywords used in the MACONF and the FILTERS file.
ACTIONTYPE Filter Keyword
The ACTIONTYPE keyword determines the type of ALERT that will be generated
when an event matching the selection criteria of the Filter is detected. The
ACTIONTYPEs are:
ALERT An EMS alert
IGNORE The event will not be added to the XMA database
IPALERT A message will be sent to an IP address, most likely to a SYSLOG
MAIL An EMAIL alert
RUNCMD XMA will kick off macro indicated
SETDATA An entry will be made in the USER_DATA column in the Audit Detail
table
SNMPTRAP A message will be sent to an SNMP TRAP
Each Filter can have multiple ACTIONTYPEs if desired, but an IGNORE must always
be the last ACTIONTYPE.
ADELMAC Macro
The ADELMAC macro is provided so that the ARCHIVE set Deletion by Date process
can be run automatically at an interval that you determine. Refer to Appendix E:XMA
Host Macrosstarting on page 203 for more information.
Alert-Only MOVERs
Alert-Only MOVERs only generate alerts. They do not update the XMA database.
Typically Alert-Only MOVERs are created for remote nodes in order to avoid the
continuous EXPAND traffic required to update the XMA database. Alert-Only MOVERs
are created in conjunction with Collect-Only MOVERs, which wake-up” during off-
peak hours to update the days audit events to the XMA database, and then go back to
sleep.
ALERT Filter Keyword
The ALERT ACTIONTYPE sends an EMS message when an event matching the
selection criteria of the Filter is detected. See also, ALERTTARGET,
ALERTSEVERITY, ALERTEMSEVENTNUMBER and ALERTSTRING.