XYGATE Merged Audit Reference Manual

Table Of Contents
XYPRO Technology Corporation 27 Proprietary and Confidential
Chapter 2. Sending Data to Your
ArcSight SIEM
This chapter describes the steps necessary to configure your XYGATE Merged Audit
installation on the HP NonStop host to send data to the ArcSight
®
SIEM.
Note: A corresponding set of parsing code must be installed on the ArcSight SIEM.
Contact your ArcSight representative to verify that you have the correct parsing
code.
2.1 What is a Log Adapter
A Log Adapter is a set of XYPRO pre-defined Filter Definitions that can be added to
your existing FILTERS file in addition to the ones that have been previously added for
other purposes.
The FILTERS file within XYGATE Merged Audit is the mechanism used to control the
inclusion or exclusion of data in the database. The FILTERS file is also used to specify
which records will be selected for transmission to a SIEM.
The XYPRO pre-defined Filter Definitions have been designed to select, categorize
and format the Merged Audit data so that it is compatible with the configuration of the
SIEM that is receiving the data.
2.2 Four Steps to Data Transmission
Before you can send data to your SIEM, there are four steps that must be performed.
Step 1. Configure XMA to Collect the Desired Data.
Step 2. Determine the Transport Method.
Step 3. Apply the Log Adapter to Your FILTERS File.
Step 4. Start and Monitor Your MOVERs.