Configuring DSMs
IBM DB2
147
Step 5
Move the .del files to a storage location where SIEM can pull the file. The
movement of the comma-delimited (.del) files should be synchronized with the file
pull interval in SIEM.
You are now ready to configure SIEM to receive DB2 log files. See
Pulling Data
Using Log File Protocol
.
Extracting Audit
Data: DB2 v8.x to
v9.4
To extract audit data when you are using IBM DB2 v8.x to v9.4.
Step 1
Log into a DB2 account with SYSADMIN privilege.
Step 2
Type the following start command to audit a database instance:
db2audit start
For example, the start command response may resemble the following:
AUD00001 Operation succeeded.
Step 3
Move the audit records from the instance to the audit log:
db2audit flush
For example, the flush command response may resemble the following:
AUD00001 Operation succeeded.
Step 4
Extract the data from the archived audit log and write the data to .del files:
db2audit extract delasc
For example, an archive command response may resemble the following:
AUD00001 Operation succeeded.
NOTE
Double-quotation marks (“) are used as the default text delimiter in the ASCII files,
do not change the delimiter.
Step 5
Remove non-active records:
db2audit prune all
Step 6
Move the .del files to a storage location where SIEM can pull the file. The
movement of the comma-delimited (.del) files should be synchronized with the file
pull interval in SIEM.
You are now ready to configure SIEM to receive DB2 log files. See
Pulling Data
Using Log File Protocol
.
Pulling Data Using
Log File Protocol
A log file protocol source allows SIEM to retrieve archived log files from a remote
host. The IBM DB2 DSM supports the bulk loading of log files using the log file
protocol source.
When configuring your IBM DB2 to use the log file protocol, make sure the
hostname or IP address configured in the IBM DB2 system is the same as
Summary of Contents for Security Information and Event Manager
Page 2: ......
Page 8: ......
Page 20: ......
Page 22: ......
Page 24: ......
Page 26: ......
Page 32: ......
Page 34: ......
Page 36: ......
Page 38: ......
Page 44: ......
Page 58: ......
Page 90: ......
Page 92: ......
Page 94: ......
Page 114: ......
Page 116: ......
Page 122: ......
Page 124: ......
Page 126: ...Configuring DSMs 110 FIREEYE...
Page 128: ......
Page 130: ......
Page 132: ......
Page 136: ......
Page 140: ......
Page 144: ......
Page 172: ......
Page 176: ...Configuring DSMs 160 ISC BIND...
Page 180: ......
Page 182: ......
Page 184: ......
Page 204: ......
Page 224: ......
Page 246: ......
Page 250: ......
Page 256: ......
Page 260: ......
Page 276: ......
Page 282: ......
Page 284: ......
Page 306: ......
Page 308: ......
Page 318: ......
Page 322: ......
Page 324: ......
Page 346: ......
Page 356: ......
Page 366: ......
Page 384: ......
Page 392: ......
Page 394: ......
Page 396: ......
Page 398: ......
Page 404: ......
Page 426: ......