XYGATE Merged Audit Reference Manual

Table Of Contents
XYGATE Merged Audit
®
Reference Manual
Contents
XYPRO Technology Corporation vi Proprietary and Confidential
2.3 Step 1. Configure XMA to Collect the Desired Data ......................... 28
2.3.1 Creating the Pathway ............................................... 28
2.3.2 Creating MOVERs ..................................................... 28
2.4 Step 2. Determine the Transport Method..................................... 28
2.4.1 Testing Your SIEM connection ...................................... 29
2.5 Step 3. Apply the Log Adapter to Your FILTERS File ........................ 30
2.5.1 Running the LAF Macro .............................................. 31
2.5.2 Changing the Transport Method from UDP to TCP .............. 31
2.5.3 Upgrading the Log Adapter Filter Definitions .................... 32
2.6 Step 4. Start and Monitor Your MOVERs....................................... 32
2.6.1 Tools for Managing Your Pathway and MOVERs .................. 32
2.6.2 Starting the Pathway ................................................ 33
2.6.3 Checking the Status of Your MOVERs .............................. 34
2.6.4 Checking the Status of an Individual MOVER ..................... 34
2.6.5 Checking the Status of the SLSENDER Process ................... 35
2.7 Additional References ........................................................... 37
Chapter 3. Configuring Filters and the FILTERS File ........................................... 39
3.1 How to Edit the FILTERS File ................................................... 40
3.2 Filter Syntax ...................................................................... 41
3.2.1 Logical ANDs and ORs................................................ 42
3.3 Building a Filter .................................................................. 44
3.3.1 Step 1. Name the Filter ............................................. 44
3.3.2 Step 2. Set the Filter Status ........................................ 44
3.3.3 Step 3: Set the EVALUATE_MSG Keyword ......................... 45
3.3.4 Step 4. Define the Filter’s Mover .................................. 46
3.3.5 Step 5. Define the Filter’s Data Selection Criteria .............. 48
3.3.6 Step 6. Define the Filter’s Action ................................. 54
3.3.7 Step 7. Syntax Check and Compile Your FILTERS File .......... 68
3.3.8 Step 8. Test Your Alerts ............................................. 70
3.4 Variable Substitution Processing in the FILTERS File ....................... 70
3.
4.1 The Text String Format ............................................. 70
3.4.2 Including a File ....................................................... 71
3.4.3 Defining a Block of Text ............................................ 72
3.4.4 General Processing Rules ........................................... 72
3.4.5 Filter Definition Example ........................................... 73
3.5 Node-Conditional Processing in the FILTERS File ............................ 73
3.5.1 Node-Conditional Operators ........................................ 74
3.6 Determine the TCP/IP Process for Email, IPALERT, SNMP Alerts .......... 75
3.6.1 Step 1. Submit a WHO command .................................. 75
3.6.2 Step 2. Submit an INFO PROCESS .................................. 76