XYGATE Merged Audit Reference Manual

Table Of Contents
XYGATE Merged Audit
®
Reference Manual
Chapter 1. Installing XMA
XYPRO Technology Corporation 12 Proprietary and Confidential
If this is a new install, you will be asked to start the LISTNER process for connection
from the PC/GUI products. Starting the LISTNER is not a requirement for the server
portion of the XMA product. It may be started at anytime. If started now, it will bind
itself to the port number you previously entered in the script.
Would you like to start the XYGATE LISTNER now ? Y
The GUI/PC modules will not be able to connect without a LISTNER set up via this
script or via the PORTCONF. Refer to the GUI Product User Guides for more
information on LISTNERs.
XYLISTEN has bound to port : 11211
Listner process $X491 started.
Taking inventory ...
Taking inventory complete.
Validating the installation ...
A final status screen will be displayed to display the current XMA environment.
XMA is currently started (Pathmon process $XMA).
Product Distribution Version Installed Version
-------- -------------------- -----------------
XMA 1.71 1.71
XTR 1.53 1.53
Listner is running and listening on port 11211.
-----------------------------------------------------------------
Validation finished. If no errors were reported, and the
information shown was as expected, the installation was
validated.
-----------------------------------------------------------------
This ends the AutoInstall installation of the XMA files. The SQL environment has been
created by the AutoInstall script.
1.3 Installing the SIEM Log Adapter
The XYGATE Merged Audit product comes with one or more adapters that can be
installed so that collected audit data will be “syslogged” to a device at a specific
IP address. Each adapter is encoded to format messages for a specific SIEM device.
Additional adapters may be available.
Note: Refer to the RSA enVision documentation and Release Notes 20110503-
142122 for the complete instructions on configuring the appliance.
1.3.1 ArcSight Adapter
Contact your ArcSight
®
representative to verify that you have the correct parsing code
in your ArcSight SIEM.