XYGATE Merged Audit Reference Manual

Table Of Contents
XYGATE Merged Audit
®
Reference Manual
Chapter 2. Sending Data to Your ArcSight SIEM
XYPRO Technology Corporation 30 Proprietary and Confidential
2.5 Step 3. Apply the Log Adapter to Your FILTERS File
Once the IP address has been verified by performing a successful test transmission,
the ArcSight Log Adapter, LAFARC, can be installed into the FILTERS file using the
LAF macro. The file LAFARC resides in the XYGATEMA subvolume.
Note: In the LAFARC file, the default transfer mechanism is UDP. If you wish to send
data via TCP, the FILTERS file will have to be updated after running the LAF
macro. Refer to the section 2.5.2, “Changing the Transport Method from UDP to
TCP” on page 31 for instructions on modifying the FILTERS file.
You should have the following information available for the adapter installation:
Prompt Description
Selection
If more than one adapter is available for installation in
the XYGATE Merged Audit product installation
location, you will be prompted to select which adapter
to install.
If only one adapter is available for installation, that
adapter is automatically selected; otherwise, the only
available adapter is automatically selected.
Enter SIEM Device IP address
<xxx.xxx.xxx.xxx>?
This is the IP address of the SIEM device where the
XYGATE Merged Audit product should syslog
messages specifically formatted for the SIEM device.
Enter TCP/IP process name
<$ZTC0>?
This is the name of the TCP/IP process through
which the SIEM device IP address is accessible.
Pressing Enter at this prompt accepts the default
value enclosed by the angle brackets < >.
The default value is the value for the define
=TCPIP^PROCESS^NAME for the current TACL
process, or if none exists, the transport process for
the TELSERV process from which the installation
procedure is being executed.
Enter TCP/IP process name for
remote node \PROD <$ZTC>?
If remote nodes exist for the XYGATE Merged Audit
installation, you will have to enter the name of the
TCP/IP process through which the SIEM device
IP address is accessible for each remote node.
The default value is the value for the define
=TCPIP^PROCESS^NAME for the current TACL
process, or if none exists, the transport process for
the TELSERV process from which the installation
procedure is being executed.