Configuring DSMs
IBM DB2
147
Step 5
Move the .del files to a storage location where SIEM can pull the file. The
movement of the comma-delimited (.del) files should be synchronized with the file
pull interval in SIEM.
You are now ready to configure SIEM to receive DB2 log files. See
Pulling Data
Using Log File Protocol
.
Extracting Audit
Data: DB2 v8.x to
v9.4
To extract audit data when you are using IBM DB2 v8.x to v9.4.
Step 1
Log into a DB2 account with SYSADMIN privilege.
Step 2
Type the following start command to audit a database instance:
db2audit start
For example, the start command response may resemble the following:
AUD00001 Operation succeeded.
Step 3
Move the audit records from the instance to the audit log:
db2audit flush
For example, the flush command response may resemble the following:
AUD00001 Operation succeeded.
Step 4
Extract the data from the archived audit log and write the data to .del files:
db2audit extract delasc
For example, an archive command response may resemble the following:
AUD00001 Operation succeeded.
NOTE
Double-quotation marks (“) are used as the default text delimiter in the ASCII files,
do not change the delimiter.
Step 5
Remove non-active records:
db2audit prune all
Step 6
Move the .del files to a storage location where SIEM can pull the file. The
movement of the comma-delimited (.del) files should be synchronized with the file
pull interval in SIEM.
You are now ready to configure SIEM to receive DB2 log files. See
Pulling Data
Using Log File Protocol
.
Pulling Data Using
Log File Protocol
A log file protocol source allows SIEM to retrieve archived log files from a remote
host. The IBM DB2 DSM supports the bulk loading of log files using the log file
protocol source.
When configuring your IBM DB2 to use the log file protocol, make sure the
hostname or IP address configured in the IBM DB2 system is the same as
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......