Configuring DSMs
282
O
RACLE
For more information about your Oracle Audit Record, see your vendor
documentation.
Oracle BEA
WebLogic
The Oracle BEA WebLogic DSM allows SIEM to retrieve archived server logs and
audit logs from any remote host, such as your Oracle BEA WebLogic server. SIEM
uses the log file protocol to retrieve events from your Oracle BEA WebLogic server
and provide information on application events that occur in your domain or on a
single server.
To integrate Oracle BEA WebLogic events, you must:
1
Enable auditing on your Oracle BEA WebLogic server. For more information, see
Enabling Event Logs on Oracle BEA WebLogic
.
2
Configure domain logging on your Oracle BEA WebLogic server. For more
information, see
Configuring Domain Logging
.
3
Configure application logging on your Oracle BEA WebLogic server.
Configuring
Application Logging
.
4
Configure an audit provider for Oracle BEA WebLogic. For more information, see
Configuring an Audit Provider
.
5
Configure SIEM to pull log files from Oracle BEA WebLogic. For more information,
see
Pulling Data Using the Log File Protocol
.
Enabling Event Logs
on Oracle BEA
WebLogic
By default, Oracle BEA WebLogic does not enable event logging. To enable event
logging on your Oracle WebLogic console:
Step 1
Log in to your Oracle WebLogic console user interface.
Step 2
Select
Domain > Configuration > General
.
Step 3
Click
Advanced
.
Step 4
From the
Configuration Audit Type
drop-down list box, select
Change Log and
Audit
.
Step 5
Click
Save
.
You are now ready to configure the collection of domain logs for Oracle BEA
WebLogic.
Configuring Domain
Logging
Oracle BEA WebLogic supports multiple instances. Event messages from
instances are collected in a single domain-wide log for the Oracle BEA WebLogic
server. To configure the log file for the domain:
Step 1
From your Oracle WebLogic console, select
Domain > Configuration > Logging
.
Step 2
From the
Log file name
parameter, type the directory path and file name for the
domain log. For example, OracleDomain.log.
Step 3
Optional. Configure any additional domain log file rotation parameters.
Summary of Contents for Security Information and Event Manager
Page 2: ......
Page 8: ......
Page 20: ......
Page 22: ......
Page 24: ......
Page 26: ......
Page 32: ......
Page 34: ......
Page 36: ......
Page 38: ......
Page 44: ......
Page 58: ......
Page 90: ......
Page 92: ......
Page 94: ......
Page 114: ......
Page 116: ......
Page 122: ......
Page 124: ......
Page 126: ...Configuring DSMs 110 FIREEYE...
Page 128: ......
Page 130: ......
Page 132: ......
Page 136: ......
Page 140: ......
Page 144: ......
Page 172: ......
Page 176: ...Configuring DSMs 160 ISC BIND...
Page 180: ......
Page 182: ......
Page 184: ......
Page 204: ......
Page 224: ......
Page 246: ......
Page 250: ......
Page 256: ......
Page 260: ......
Page 276: ......
Page 282: ......
Page 284: ......
Page 306: ......
Page 308: ......
Page 318: ......
Page 322: ......
Page 324: ......
Page 346: ......
Page 356: ......
Page 366: ......
Page 384: ......
Page 392: ......
Page 394: ......
Page 396: ......
Page 398: ......
Page 404: ......
Page 426: ......