Configuring DSMs
280
O
RACLE
Step 9
Click
Save
.
Step 10
On the
Admin
tab, click
Deploy Changes
.
NOTE
The local time zone conversion-dependent Oracle timestamps are not supported
in earlier versions of the JDBC protocol for SIEM so fields AV_ALERT_TIME,
ACTUAL_ALERT_TIME, and TIME_CLEARED in the payload only display object
identifiers until your JDBC protocol is updated.
Oracle OS Audit
The SIEM Oracle OS Audit DSM allows monitoring of the audit records that are
stored in the local operating system file. When audit event files are created or
updated in the local operating system directory, a Perl script detects the change,
and forwards the data to SIEM. The Perl script monitors the Audit log file,
combines any multi-line log entries into a single log entry to ensure the logs are not
forwarded line-by-line, as is found in the log file, then sends the logs using syslog
to SIEM. Perl scripts written for Oracle OS Audit work on Linux/UNIX servers only.
Windows Perl script is not supported.
NOTE
To avoid errors, do not delete log files you are actively monitoring unless the script
is stopped, or processing is complete.
To integrate the Oracle OS Audit DSM with SIEM:
Step 1
Access the Enterasys Extranet:
http://extranet.enterasys.com/downloads/
Step 2
Download the following Oracle OS Audit DSM files:
oracle_osauditlog_fwdr.pl.gz
Step 3
Unzip the file:
gzip -d oracle_osauditlog_fwdr.pl.gz
Step 4
Copy the Perl script to the server that hosts the Oracle server.
NOTE
Perl 5.8 must be installed on the device that hosts the Oracle server.
Step 5
Log in to the Oracle host as an Oracle user that has SYS or root privilege.
Step 6
Make sure the ORACLE_HOME and ORACLE_SID environment variables are
configured properly for your deployment.
Step 7
Open the following file:
${ORACLE_HOME}/dbs/init${ORACLE_SID}.ora
Step 8
For syslog, add the following lines to the file:
*.audit_trail=’os’
*.audit_syslog_level=’local0.info’
Step 9
Verify account has read/write permissions for the following directories:
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......