Configuring DSMs
Oracle Audit Vault
279
event can be mapped to a high-level and low-level category (or QID). Using the
Oracle Audit Vault DSM, category mapping can be done by mapping your high or
low category alerts directly to an alert name (ALERT_NAME field) in the payload.
For information about the Events interface, see the SIEM Users Guide.
To configure Oracle Audit Vault DSM with SIEM, see
Configuring SIEM to Receive
Oracle Audit Vault Alerts
.
Configuring SIEM to
Receive Oracle Audit
Vault Alerts
To configure SIEM to access the Oracle Audit Vault database using the JDBC
protocol:
Step 1
Log in to SIEM.
Step 2
Click the
Admin
tab.
Step 3
In the navigation menu, click
Data Sources
.
The Data Sources panel is displayed.
Step 4
Click the
Log Sources
icon.
The Log Sources window is displayed.
Step 5
Click
Add
.
Step 6
Using the
Log Source Type
drop-down list box, select
Oracle Audit Vault
.
Step 7
Using the
Protocol Configuration
drop-down list box, select
JDBC
.
Step 8
Configure the following values:
a
Database Type:
Oracle
b
Database Name: <
Audit Vault Database Name
>
c
Table Name:
avsys.av$alert_store
d
Select List:
*
e
Compare Field:
ALERT_SEQUENCE
f
IP or Hostname: <
Location of Oracle Audit Vault Server
>
g
Port: <
Default Port
>
h
Username: <
Database Access Username having AV_AUDITOR role
>
i
Password: <
Password
>
j
Polling Interval: <
Default Interval
>
NOTE
Verify the AV_AUDITOR password has been entered correctly before saving the
JDBC protocol configuration. Oracle Audit Vault may lock the user account due to
repeated failed login attempts. When the AV_AUDITOR account is locked, data in
the avsys.av$alert_store cannot be accessed. In order to unlock this user
account, it is necessary to first correct the password entry in the protocol
configuration. Then log in to Oracle Audit Vault through the Oracle sqlplus prompt
as the avadmindva user to perform an alter user <AV_AUDITOR USER> account
unlock command.
Summary of Contents for Security Information and Event Manager
Page 2: ......
Page 8: ......
Page 20: ......
Page 22: ......
Page 24: ......
Page 26: ......
Page 32: ......
Page 34: ......
Page 36: ......
Page 38: ......
Page 44: ......
Page 58: ......
Page 90: ......
Page 92: ......
Page 94: ......
Page 114: ......
Page 116: ......
Page 122: ......
Page 124: ......
Page 126: ...Configuring DSMs 110 FIREEYE...
Page 128: ......
Page 130: ......
Page 132: ......
Page 136: ......
Page 140: ......
Page 144: ......
Page 172: ......
Page 176: ...Configuring DSMs 160 ISC BIND...
Page 180: ......
Page 182: ......
Page 184: ......
Page 204: ......
Page 224: ......
Page 246: ......
Page 250: ......
Page 256: ......
Page 260: ......
Page 276: ......
Page 282: ......
Page 284: ......
Page 306: ......
Page 308: ......
Page 318: ......
Page 322: ......
Page 324: ......
Page 346: ......
Page 356: ......
Page 366: ......
Page 384: ......
Page 392: ......
Page 394: ......
Page 396: ......
Page 398: ......
Page 404: ......
Page 426: ......