XYGATE Merged Audit Reference Manual

Table Of Contents
XYGATE Merged Audit
®
Reference Manual
Glossary
XYPRO Technology Corporation 305 Proprietary and Confidential
ALERTTOKENS Filter Keyword
This is a list of columns you wish to display from the AUDIT DETAIL TBL, and AUDIT
SESSION TBL.
The default is all of the data from the AUDIT DETAIL TBL and AUDIT SESSION TBL.
Syntax:
ALERTTOKENS <column>...< column > ALERTTOKENSEND
APPMOVE Program
APPMOVE is the program that reads the iTP Secure WebServer audits.
APXMLITP File
The APXMLITP File contains information that is used by the APPMOVE program to
process iTP Secure Webserver audits. This file must be accompanied by a signature
file.
ARCHIVE Macro
The ARCHIVE macro removes data from the active XMA SQL database and places
the information in a set of ARCHIVE tables. This process can be automated by
creating a batch job to kick off the macro. The ARCMAC file in the XYGATEMA
subvolume is a sample batch job that you can use as a template for creating your own.
See also ARCMAC File and Chapter 6, “Configuring MOVERs” starting on page 109
for more information.
ARCMAC File
ARCMAC is a sample ARCHIVE batch job. Customize it for your environment if you
plan to archive your XMA data tables. Refer to Appendix E:XMA Host Macros
starting on page 203 for more information.
Collect-Only MOVERs
Collect-Only MOVERs only update the XMA database. They do not generate alerts.
Collectonly MOVERs are generally created in conjunction with Alert-Only MOVERs,
which provide the alerts for the activity on the remote nodes. Typically, Collect-Only
MOVERs are created for remote nodes to avoid the continuous EXPAND traffic
required to update the XMA database. They wake-upduring off peak hours to update
the day’s audit events to the XMA database and then are put back to sleep.
Collection Window
This is the time when the Collect-Only Serverclasses will “wake-upto update the XMA
database and when the MOVER will be put back to sleep.When you create a
MOVER designated as Collect-Only, you will be asked to specify acollection window
during installation. To change the Collection Window, use Movers Management Menu,
option 20: Alert-Only/Collect-Only/Regular Movers on page 101.