XYGATE Merged Audit Reference Manual

Table Of Contents
XYGATE Merged Audit
®
Reference Manual
Chapter 2. Sending Data to Your ArcSight SIEM
XYPRO Technology Corporation 28 Proprietary and Confidential
2.3 Step 1. Configure XMA to Collect the Desired Data
Before data can be transmitted to your SIEM, XYGATE Merged Audit must be installed
and configured to collect the desired data.
2.3.1 Creating the Pathway
As part of the installation process, a pathway is created. The pathway runs
serverclasses that perform housekeeping tasks, collect data, issue alerts and transmit
data. If the pathway and serverclasses are not running, no data will be collected or
transmitted.
2.3.2 Creating MOVERs
XMA has the ability to collect data from various sources on the HP NonStop server.
These sources include HP audit files and logs, XYGATE product audit files, and data
from a number of third-party vendors. The data are collected via a set of programs
running as Pathway serverclasses. These serverclasses are referred to as MOVERs.
Each MOVER is dedicated to a specific set of audit files or logs.
If XMA was installed using AutoInstall (XAI) or XYGATE Master Installer (XMI), a set of
MOVERs will have been automatically created for a number of HP products and any
XYGATE products currently installed on your system. However, MOVERs are not
automatically installed for the iTP Secure Webserver, Home Location Register (HLR)
or BASE24-eps.
Note: The owner of the XMA application must have Read access to all the desired
data sources.
2.4 Step 2. Determine the Transport Method
Data can be transported to a SIEM via two methods: UDP or TCP. You will have to
check with the individuals responsible for managing the device to see which method
the SIEM will accept and the correct configuration information. They will also be able to
provide you with the device’s IP address. XMA supports only IPV4 format addresses
for data transmission.
Note: Make sure the firewall will allow transmission of the data.
Note: If you will be sending data via TCP, the SLSENDER serverclass has to be
configured and started. The SYSLOGQ server is configured via the Movers
Management Menu, option 18 (page 101).