XYGATE Merged Audit Reference Manual

Table Of Contents
XYGATE Merged Audit
®
Reference Manual
Glossary
XYPRO Technology Corporation 309 Proprietary and Confidential
IPALERT Filter Keyword
The IPALERT ACTIONTYPE sends an ALERT message to a TCP/IP address or
'SYSLOG' console when an event matching the selection criteria of the Filter is
detected. See also, ALERTSTRING, IPALERT_ADDRESS, IPALERT_PORT,
IPALERT_PREFIX and IPALERT_PROCESS.
IPALERT_ADDRESS Filter Keyword
Filters with an IPALERT ACTIONTYPE require the IPALERT_ADDRESS keyword to
define the TCP/IP address where XMA will send the string meant for a SYSLOG. This
keyword is required for IPALERT actions.
IPALERT_PORT Filter Keyword
Filters with an IPALERT ACTIONTYPE require the IPALERT_PORT keyword to define
the port on the remote system where XMA will send the string meant for a SYSLOG.
This keyword is required for IPALERT actions. Port 25 is the expected value.
IPALERT_PREFIX Filter Keyword
Filters with an IPALERT ACTIONTYPE require the IPALERT_PREFIX keyword to
define the prefix that will be appended to the SYSLOG message. This is optional and
can be up to 79 characters in length. For non-SYSLOGQ messages the length can be
up to 40 characters. Data Substitution tokens are not permitted.
IPALERT_PROCESS Filter Keyword
Filters with an IPALERT ACTIONTYPE require the IPALERT_PROCESS keyword to
define the TCP/IP process that manages the PORT where the IPALERT message will
be sent.
LOCATION MOVER Criteria Keyword
The volume and subvolume location of the MOVER’s target product. You only need to
specify the product LOCATION if you have multiple copies of the same XYGATE
product on the same system and you want to alert on events from one installation but
not another. If the LOCATION keyword is not present, MOVERs for all of the
installations will compare their audit events against the Filter.
MAACL File
The MAACL file exists only for standardization with other XYGATE products. The file is
not used by XMA in any way.
MAHELP File
Contains a list of the macros available on the host for maintaining XMA and running
reports on the host.