Configuring DSMs
48
N
OVELL
E
D
IRECTORY
A SIEM Novell eDirectory DSM accepts audit events from Novell eDirectory using
syslog. To use the Novell eDirectory DSM, you must have the following
components installed:
•
Novell eDirectory v8.8 with service pack 6 (sp6)
•
Novell iManager v2.7
•
XDASv2
To configure Novell eDirectory with SIEM, you must:
1
Configure the XDASv2 property file to forward events to SIEM. For more
information, see
Configuring XDASv2 to Forward Events
.
2
Load the XDASv2 module on your Linux or Windows Operating System. For more
information, see
Loading the XDASv2 Module
.
3
Configure auditing using Novell iManager. For more information, see
Configuring
Event Auditing Using Novell iManager
.
4
Configure SIEM. For more information, see
Configuring SIEM with Novell
eDirectory
.
Configuring XDASv2
to Forward Events
By default, XDASv2 is configured to log events to a file. To forward events from
XDASv2 to SIEM, you must edit the xdasconfig.properties and configure the file for
syslog forwarding. Audit events must be forwarded by syslog to SIEM, instead of
being logged to a file.
To configure XDASv2 to forward syslog events:
Step 1
Log in to the server hosting Novell eDirectory.
Step 2
Open the following file for editing:
•
Windows
-
C:\Novell\NDS\xdasconfig.properties
•
Linux or Solaris
-
etc/opt/novell/configuration/xdasconfig.properties
Step 3
To set the root logger, remove the comment marker (#) from the following line:
log4j.rootLogger=debug, S, R
Step 4
To set the appender, remove the comment marker (#) from the following line:
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......