Configuring DSMs
276
O
RACLE
Step 8
Click
Save
.
The configuration of the Oracle Database Listener protocol is complete. For more
information, see the
Log Sources User Guide
.
Collecting Oracle
Database Events
Using Perl and
Syslog
The Oracle Database Listener application stores logs on the database server. To
forward these logs from the Oracle server to SIEM, you must configure a Perl
script on the Oracle server. The Perl script monitors the listener log file, combines
any multi-line log entries into a single log entry, and sends the logs, using syslog
(UDP), to SIEM.
Before being sent to SIEM, the logs are processed and re-formatted to ensure the
logs are not forwarded line-by-line, as is found in the log file. All of the relevant
information is retained.
NOTE
Perl scripts written for Oracle DB listener work on Linux/UNIX servers only.
Windows Perl script is not supported.
To install and configure the Perl script:
Step 1
Access the Enterasys Extranet:
http://extranet.enterasys.com/downloads/
Step 2
Download the script to forward the Oracle DB Listener events.
oracle_dblistener_fwdr.pl.txt
Step 3
Rename the file to a Perl script.
Force File Read
Select the check box to force the protocol to read the log file
when the timing of the polling interval specifies.
When the check box is selected, the log file source is always
examined when the polling interval specifies, regardless of
the last modified time or file size attribute.
When the check box is not selected, the log file source is
examined at the polling interval if the last modified time or file
size attributes have changed.
Recursive
Select the check box if you want the file pattern to also
search sub folders. By default, the check box is selected.
Polling Interval (in
seconds)
Type the polling interval, which is the number of seconds
between queries to the log files to check for new data. The
minimum polling interval is 10 seconds, with a maximum
polling interval of 3,600 seconds. The default is 10 seconds.
Throttle Events/Sec
Type the maximum number of events the Oracle Database
Listener protocol forwards per second. The minimum value is
100 EPS and the maximum is 20,000 EPS. The default is
100 EPS.
Table 51-3
Oracle
Database Listener Parameters (continued)
Parameter
Description
Summary of Contents for Security Information and Event Manager
Page 2: ......
Page 8: ......
Page 20: ......
Page 22: ......
Page 24: ......
Page 26: ......
Page 32: ......
Page 34: ......
Page 36: ......
Page 38: ......
Page 44: ......
Page 58: ......
Page 90: ......
Page 92: ......
Page 94: ......
Page 114: ......
Page 116: ......
Page 122: ......
Page 124: ......
Page 126: ...Configuring DSMs 110 FIREEYE...
Page 128: ......
Page 130: ......
Page 132: ......
Page 136: ......
Page 140: ......
Page 144: ......
Page 172: ......
Page 176: ...Configuring DSMs 160 ISC BIND...
Page 180: ......
Page 182: ......
Page 184: ......
Page 204: ......
Page 224: ......
Page 246: ......
Page 250: ......
Page 256: ......
Page 260: ......
Page 276: ......
Page 282: ......
Page 284: ......
Page 306: ......
Page 308: ......
Page 318: ......
Page 322: ......
Page 324: ......
Page 346: ......
Page 356: ......
Page 366: ......
Page 384: ......
Page 392: ......
Page 394: ......
Page 396: ......
Page 398: ......
Page 404: ......
Page 426: ......