Configuring DSMs
280
O
RACLE
Step 9
Click
Save
.
Step 10
On the
Admin
tab, click
Deploy Changes
.
NOTE
The local time zone conversion-dependent Oracle timestamps are not supported
in earlier versions of the JDBC protocol for SIEM so fields AV_ALERT_TIME,
ACTUAL_ALERT_TIME, and TIME_CLEARED in the payload only display object
identifiers until your JDBC protocol is updated.
Oracle OS Audit
The SIEM Oracle OS Audit DSM allows monitoring of the audit records that are
stored in the local operating system file. When audit event files are created or
updated in the local operating system directory, a Perl script detects the change,
and forwards the data to SIEM. The Perl script monitors the Audit log file,
combines any multi-line log entries into a single log entry to ensure the logs are not
forwarded line-by-line, as is found in the log file, then sends the logs using syslog
to SIEM. Perl scripts written for Oracle OS Audit work on Linux/UNIX servers only.
Windows Perl script is not supported.
NOTE
To avoid errors, do not delete log files you are actively monitoring unless the script
is stopped, or processing is complete.
To integrate the Oracle OS Audit DSM with SIEM:
Step 1
Access the Enterasys Extranet:
http://extranet.enterasys.com/downloads/
Step 2
Download the following Oracle OS Audit DSM files:
oracle_osauditlog_fwdr.pl.gz
Step 3
Unzip the file:
gzip -d oracle_osauditlog_fwdr.pl.gz
Step 4
Copy the Perl script to the server that hosts the Oracle server.
NOTE
Perl 5.8 must be installed on the device that hosts the Oracle server.
Step 5
Log in to the Oracle host as an Oracle user that has SYS or root privilege.
Step 6
Make sure the ORACLE_HOME and ORACLE_SID environment variables are
configured properly for your deployment.
Step 7
Open the following file:
${ORACLE_HOME}/dbs/init${ORACLE_SID}.ora
Step 8
For syslog, add the following lines to the file:
*.audit_trail=’os’
*.audit_syslog_level=’local0.info’
Step 9
Verify account has read/write permissions for the following directories:
Summary of Contents for Security Information and Event Manager
Page 2: ......
Page 8: ......
Page 20: ......
Page 22: ......
Page 24: ......
Page 26: ......
Page 32: ......
Page 34: ......
Page 36: ......
Page 38: ......
Page 44: ......
Page 58: ......
Page 90: ......
Page 92: ......
Page 94: ......
Page 114: ......
Page 116: ......
Page 122: ......
Page 124: ......
Page 126: ...Configuring DSMs 110 FIREEYE...
Page 128: ......
Page 130: ......
Page 132: ......
Page 136: ......
Page 140: ......
Page 144: ......
Page 172: ......
Page 176: ...Configuring DSMs 160 ISC BIND...
Page 180: ......
Page 182: ......
Page 184: ......
Page 204: ......
Page 224: ......
Page 246: ......
Page 250: ......
Page 256: ......
Page 260: ......
Page 276: ......
Page 282: ......
Page 284: ......
Page 306: ......
Page 308: ......
Page 318: ......
Page 322: ......
Page 324: ......
Page 346: ......
Page 356: ......
Page 366: ......
Page 384: ......
Page 392: ......
Page 394: ......
Page 396: ......
Page 398: ......
Page 404: ......
Page 426: ......