XYGATE Merged Audit Reference Manual

Table Of Contents
XYGATE Merged Audit
®
Reference Manual
Chapter 2. Sending Data to Your ArcSight SIEM
XYPRO Technology Corporation 31 Proprietary and Confidential
2.5.1 Running the LAF Macro
This macro is run from the XYGATEMA subvolume. From the TACL prompt, enter
LAF. You do not have to install the XMA segment prior to running the LAF macro.
$PROD.XYGATEMA 1> RUN LAF
XYGATEMA Adapter Installer version 1.14.
Checking owner, version, and installed filter ...
Checks complete.
Sel File Description
--- -------- ------------------------------------------------------------------
1 LAFARC ArcSight Log Adapter Filters - Version 1.02
Selection? 1
Enter SIEM Device IP address <xxx.xxx.xxx.xxx>? 10.1.1.x
Enter TCP/IP process name <$ZTCP2>?
Pinging 10.1.1.x using $ZTCP2 ...
Ping of 10.1.1.x succeeded.
If the XYGATE Merged Audit installation contains remote nodes, the following dialog
will occur for each one:
Enter TCP/IP process name for remote node \PROD2 <$ZTC0>? $ZTCP2
Pinging 10.1.1.x using \PROD2.$ZTCP2 ...
Ping of 10.1.1.x using \PROD2.$ZTCP2 succeeded.
The LAF adapter installer will install the adapter into a copy of the FILTERS file.
Building filter. This may take several minutes ...
The created FILTERS copy will be checked for syntax errors. If no errors exist, the
original FILTERS file will be renamed as a backup, and the copy will be renamed to
become the new FILTERS file; otherwise, you will be directed to review the file
LOGFILT for specific errors.
Filter built.
To back out changes, replace FILTERS with OLDFLT01.
$PROD.XYGATEMA 2>
2.5.2 Changing the Transport Method from UDP to TCP
Within the FILTERS file, the transport method is designated via the ACTIONTYPE
keyword and its associated value.
Specifying ACTIONTYPE IPALERT will send data via UDP. Specifying ACTIONTYPE
SYSLOGQ will send data via TCP.
Note: If you will be sending data via TCP, the SLSENDER serverclass has to be
configured and started. The SYSLOGQ server is configured via the Movers
Management Menu, option 18 (page 101).
1. Using the XYGATE Configuration (XCF) GUI or the XMA_EDIT_FILTERS macro,
locate the text: !Begin ArcSight Log Adapter Filters.