Configuring DSMs
276
O
RACLE
Step 8
Click
Save
.
The configuration of the Oracle Database Listener protocol is complete. For more
information, see the
Log Sources User Guide
.
Collecting Oracle
Database Events
Using Perl and
Syslog
The Oracle Database Listener application stores logs on the database server. To
forward these logs from the Oracle server to SIEM, you must configure a Perl
script on the Oracle server. The Perl script monitors the listener log file, combines
any multi-line log entries into a single log entry, and sends the logs, using syslog
(UDP), to SIEM.
Before being sent to SIEM, the logs are processed and re-formatted to ensure the
logs are not forwarded line-by-line, as is found in the log file. All of the relevant
information is retained.
NOTE
Perl scripts written for Oracle DB listener work on Linux/UNIX servers only.
Windows Perl script is not supported.
To install and configure the Perl script:
Step 1
Access the Enterasys Extranet:
http://extranet.enterasys.com/downloads/
Step 2
Download the script to forward the Oracle DB Listener events.
oracle_dblistener_fwdr.pl.txt
Step 3
Rename the file to a Perl script.
Force File Read
Select the check box to force the protocol to read the log file
when the timing of the polling interval specifies.
When the check box is selected, the log file source is always
examined when the polling interval specifies, regardless of
the last modified time or file size attribute.
When the check box is not selected, the log file source is
examined at the polling interval if the last modified time or file
size attributes have changed.
Recursive
Select the check box if you want the file pattern to also
search sub folders. By default, the check box is selected.
Polling Interval (in
seconds)
Type the polling interval, which is the number of seconds
between queries to the log files to check for new data. The
minimum polling interval is 10 seconds, with a maximum
polling interval of 3,600 seconds. The default is 10 seconds.
Throttle Events/Sec
Type the maximum number of events the Oracle Database
Listener protocol forwards per second. The minimum value is
100 EPS and the maximum is 20,000 EPS. The default is
100 EPS.
Table 51-3
Oracle
Database Listener Parameters (continued)
Parameter
Description
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......