Security Considerations for Sentinel Log Manager
19
no
vd
ocx
(e
n)
19
Fe
bru
a
ry
20
10
Table 2-2
Locations for Configuration Data and Event Data
2.4 Securing the Operating System
Sentinel Log Manager is supported on SUSE
®
Linux Enterprise Server (SLES) 11. For more
information on securing a SLES machine, see the
SUSE Linux Enterprise Server 11
documentation (http://www.novell.com/documentation/sles11/book_sle_security/?page=/
documentation/sles11/book_sle_security/data/book_sle_security.html)
.
If the Sentinel Log Manager is accessible from outside the corporate network, a firewall should
be employed to prevent direct access to the Sentinel Log Manager server.
Enable the following ports in the firewall:
Table 2-3
List of Components and their Ports
Components
Location for Configuration Data
Location for Event Data
Event Data
The database tables and file system
at
Install_Directory
/config
.
This configuration information
includes the encrypted database,
event source, integrators, and
passwords.
The database (EVENTS,
CORRELATED_EVENTS, and the
EVT_SMRY_* and
AUDIT_RECORD tables), and the
file system at
Install_Directory
/data/
events
.
NOTE:
Event data can be archived
to the file system as part of the
partition management job.
Collector Manager
The file system at
Install_Directory
/data/
eventdata
and
Install_Directory
/data/
rawdata
. The most sensitive
configuration information is the
client key pair used to connect to the
message bus.
Event data might be cached on the
file system during error conditions
such as the message bus being
down or event overflow. This event
data is stored in the
Install_Directory
/data/
collector_mgr.cache
directory.
Component
Port
ActiveMQ
61616 and 61617
PostgreSQL
5432
Tomcat
8443
Proxied trusted client
10014
internal_gateway_server and internal_gateway
Used between the engine and the manager
5556
Event Source Management user interface SSL
Proxy
10013
Audit Connector
1289
Содержание SENTINEL LOG MANAGER 1.0.0.5 - 03-31-2010
Страница 4: ...4 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Страница 46: ...46 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Страница 74: ...74 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Страница 140: ...140 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Страница 146: ...146 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Страница 148: ...148 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Страница 158: ...158 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Страница 166: ...166 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Страница 168: ...168 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...