Configuring DSMs
272
O
RACLE
To configure an Oracle Audit device to write audit logs to SIEM, see
Integrating
Oracle Audit Device with SIEM
. If your system includes a large Oracle audit table
(greater than 1 GB), see
Improving Performance With Large Audit Tables
.
Integrating Oracle
Audit Device with
SIEM
To configure the device to write audit logs:
Step 1
Log in to the Oracle host as an Oracle user (This user was used to install Oracle,
for example oracle).
Step 2
Make sure the ORACLE_HOME and ORACLE_SID environment variables are
configured properly for your deployment.
Step 3
Open the following file:
${ORACLE_HOME}/dbs/init${ORACLE_SID}.ora
Step 4
Choose one of the following options:
a
For database audit trails, type the following command:
*.audit_trail=’DB’
b
For syslog, type the following command:
*.audit_trail=’os’
*.audit_syslog_level=’local0.info’
You must make sure the syslog daemon on the Oracle host is configured to
forward the audit log to SIEM. For systems running Red Hat Enterprise, the
following line in the
/etc/syslog.conf
file effects the forwarding:
local0.info @siem.domain.tld
Where
siem.domain.tld
is the hostname of the SIEM system that receives
the events. The syslog configuration must be re-loaded for the above command
to be recognized. On a system running Red Hat Enterprise, type the following
line to reload the syslog configuration:
kill -HUP /var/run/syslogd.pid
Step 5
Save and exit the file.
Step 6
To restart the database:
a
Connect to SQLplus and log in as sysdba:
For example,
Enter user-name: sys as sysdba
b
Shut down the database:
shutdown immediate
c
Restart the database:
startup
Summary of Contents for Security Information and Event Manager
Page 2: ......
Page 8: ......
Page 20: ......
Page 22: ......
Page 24: ......
Page 26: ......
Page 32: ......
Page 34: ......
Page 36: ......
Page 38: ......
Page 44: ......
Page 58: ......
Page 90: ......
Page 92: ......
Page 94: ......
Page 114: ......
Page 116: ......
Page 122: ......
Page 124: ......
Page 126: ...Configuring DSMs 110 FIREEYE...
Page 128: ......
Page 130: ......
Page 132: ......
Page 136: ......
Page 140: ......
Page 144: ......
Page 172: ......
Page 176: ...Configuring DSMs 160 ISC BIND...
Page 180: ......
Page 182: ......
Page 184: ......
Page 204: ......
Page 224: ......
Page 246: ......
Page 250: ......
Page 256: ......
Page 260: ......
Page 276: ......
Page 282: ......
Page 284: ......
Page 306: ......
Page 308: ......
Page 318: ......
Page 322: ......
Page 324: ......
Page 346: ......
Page 356: ......
Page 366: ......
Page 384: ......
Page 392: ......
Page 394: ......
Page 396: ......
Page 398: ......
Page 404: ......
Page 426: ......