XYGATE Merged Audit Reference Manual

Table Of Contents
XYGATE Merged Audit
®
Reference Manual
Chapter 3. Configuring Filters and the FILTERS File
XYPRO Technology Corporation 46 Proprietary and Confidential
3.3.4 Step 4. Define the Filters Mover
In most cases, you will only use the PRODUCT keyword to select a MOVER, but you
may also select the node on which the target product resides and the subvolume the
product is running from.
Remember that the MOVER Serverclasses are the programs actually reading the
various audit trails and transferring the records to the XMA database and generating
any ACTIONs that you define. Each MOVER compares its audit events against Filters
in the FILTERS file.
Within a Filter, you use the MOVER selection criteria to control which MOVER(s) will
compare audit records against the Filter’s data selection criteria to determine if
ACTION(s) should be taken.
The MOVER selection criteria is optional in Filters, but you can save some processing
overhead by defining MOVERs for all your Filters. This is because all MOVERs will
compare their audit events against the Filter unless you specify a MOVER in a Filter.
If you do specify a MOVER, then only the MOVER(s) for the selected product(s) will
compare audit events against that Filter.
If you do not specify a node in the MOVER selection criteria, then the MOVERs for the
product on all the nodes will use the Filter.
If you do specify a node, then only the MOVER(s) for that product on the specified
node will use the Filter.
Syntax:
<MOVER keyword> <operator> <MOVER selection criteria>
MOVER Selection Keywords
MOVER selection criteria is based entirely on the product whose audit trail the
MOVER is reading. There are three criteria for MOVERs:
PRODUCT This keyword is used to specify the desired MOVERs target
product. Enter the full product name as follows:
BASE24
EMS
HLR
MEASURE
SAFEGUARD
XYGATExx
FILEMAINT
ITP