Configuring DSMs
48
N
OVELL
E
D
IRECTORY
A SIEM Novell eDirectory DSM accepts audit events from Novell eDirectory using
syslog. To use the Novell eDirectory DSM, you must have the following
components installed:
•
Novell eDirectory v8.8 with service pack 6 (sp6)
•
Novell iManager v2.7
•
XDASv2
To configure Novell eDirectory with SIEM, you must:
1
Configure the XDASv2 property file to forward events to SIEM. For more
information, see
Configuring XDASv2 to Forward Events
.
2
Load the XDASv2 module on your Linux or Windows Operating System. For more
information, see
Loading the XDASv2 Module
.
3
Configure auditing using Novell iManager. For more information, see
Configuring
Event Auditing Using Novell iManager
.
4
Configure SIEM. For more information, see
Configuring SIEM with Novell
eDirectory
.
Configuring XDASv2
to Forward Events
By default, XDASv2 is configured to log events to a file. To forward events from
XDASv2 to SIEM, you must edit the xdasconfig.properties and configure the file for
syslog forwarding. Audit events must be forwarded by syslog to SIEM, instead of
being logged to a file.
To configure XDASv2 to forward syslog events:
Step 1
Log in to the server hosting Novell eDirectory.
Step 2
Open the following file for editing:
•
Windows
-
C:\Novell\NDS\xdasconfig.properties
•
Linux or Solaris
-
etc/opt/novell/configuration/xdasconfig.properties
Step 3
To set the root logger, remove the comment marker (#) from the following line:
log4j.rootLogger=debug, S, R
Step 4
To set the appender, remove the comment marker (#) from the following line:
Summary of Contents for Security Information and Event Manager
Page 2: ......
Page 8: ......
Page 20: ......
Page 22: ......
Page 24: ......
Page 26: ......
Page 32: ......
Page 34: ......
Page 36: ......
Page 38: ......
Page 44: ......
Page 58: ......
Page 90: ......
Page 92: ......
Page 94: ......
Page 114: ......
Page 116: ......
Page 122: ......
Page 124: ......
Page 126: ...Configuring DSMs 110 FIREEYE...
Page 128: ......
Page 130: ......
Page 132: ......
Page 136: ......
Page 140: ......
Page 144: ......
Page 172: ......
Page 176: ...Configuring DSMs 160 ISC BIND...
Page 180: ......
Page 182: ......
Page 184: ......
Page 204: ......
Page 224: ......
Page 246: ......
Page 250: ......
Page 256: ......
Page 260: ......
Page 276: ......
Page 282: ......
Page 284: ......
Page 306: ......
Page 308: ......
Page 318: ......
Page 322: ......
Page 324: ......
Page 346: ......
Page 356: ......
Page 366: ......
Page 384: ......
Page 392: ......
Page 394: ......
Page 396: ......
Page 398: ......
Page 404: ......
Page 426: ......