Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

Version 1 Current »

About the Device

 eDirectory is the foundation for the world's largest identity management deployments and is a high-end directory service that allows businesses to manage identities and security access for employees, customers, and partners. With eDirectory, businesses lay the groundwork for secure identity management solutions and multi-platform network services. eDirectory provides centralized identity management, infrastructure, Net-wide security and scalability to all types of applications running behind and beyond the firewall.

Device Information

 Entity

Particulars

Vendor Name

Microfocus

Product Name

NetIQ eDirectory

Type of Device

Hosted

Collection Method

Log Type

 Ingestion label

Preferred Logging Protocol - Format

Log collection method

 NetIQ eDirectory

 NETIQ_EDIRECTORY

 Syslog - CEF

CyberHub

Port Requirements

Source

Destination

Port

 Microfocus NetIQ eDirectory

CyberHub

6514 (TCP)

Device Configuration

Pre-requisites :

Configuring CEF Package : The eDirectory installation kit includes both a Linux and a Windows CEF client as part of its download package. The installation program for eDirectory installs the CEF packages on your operating system.

System Requirements : NetIQ Audit iManager Plug-in requires iManager 3.1 at a minimum

Configuring the CEF Property File :

The eDirectory media includes a sample properties file, auditlogconfig.properties.template file in the configdir (n4u.server.configdir) directory.

Location of the Property File :

Operating System

Location of the Property File

Linux

/etc/opt/novell/eDirectory/conf/auditlogconfig.properties

Windows

<Install Path>/novell/nds/auditlogconfig.properties

The CEF auditlogconfig.properties file for windows contains the following information:

# Brief description for appenders and their options are provided.
# For detailed decriptions refer to log4cxx documentation.

# Set the level of the root logger to DEBUG and attach appenders.
log4j.rootLogger=debug, S

# Defines appender S to be a SyslogAppender.
log4j.appender.S=org.apache.log4j.net.SyslogAppender

# Defines location of Syslog server.
log4j.appender.S.Host=<CyberHub IP>
log4j.appender.S.Port=<port>

# Specify protocol to be used (UDP/TCP/SSL).
log4j.appender.S.Protocol=SSL

# Specify SSL certificate file for SSL connection.
# File path should be given with double backslash.
log4j.appender.S.SSLCertFile=C:\\Novell\\mycert.pem

# Minimum log-level allowed in syslog.
log4j.appender.S.Threshold=INFO

# Defines the type of facility.
log4j.appender.S.Facility=USER

# Defines caching for SyslogAppender.
# Inputs should be yes/no
log4j.appender.S.CacheEnabled=yes

# Cache location directory
# Directory should be available for creating cache files
log4j.appender.S.CacheDir=C:\\NetIQ\\eDirectory

# Cache File Size
# Cache File size should be in the range of 50MB to 4000MB in limited growth mode
log4j.appender.S.CacheMaxFileSize=500MB

# Layout definition for appender Syslog S.
log4j.appender.S.layout=org.apache.log4j.PatternLayout
log4j.appender.S.layout.ConversionPattern=%c: %m%n

# Defines appender R to be a Rolling File Appender.
log4j.appender.R=org.apache.log4j.RollingFileAppender

# Log file for appender R.
# File path should be given with double backslash.
log4j.appender.R.File=C:\\cef-events.log

# Max size of log file for appender R.
log4j.appender.R.MaxFileSize=100MB

# Set the maximum number of backup files to keep for appender R.
# Max can be 13. If set to zero, then there will be no backup files.
log4j.appender.R.MaxBackupIndex=10

# Layout definition for appender Rolling log file R.
log4j.appender.R.layout=org.apache.log4j.PatternLayout
log4j.appender.R.layout.ConversionPattern=%d{MMM dd HH:mm:ss} %c %m%n

You must restart eDirectory after changing any configuration.

Replace the above Windows Commands if LINUX OS is used :

Windows

Linux

#log4j.appender.S.SSLCertFile=C:\\Novell\\mycert.pem

#log4j.appender.S.SSLCertFile=etc/opt/novell/mycert.pem

#log4j.appender.S.CacheDir=C:\\NetIQ\\eDirectory

#log4j.appender.S.CacheDir=/var/opt/novell/eDirectory

#log4j.appender.R.File=C:\\cef-events.log

#log4j.appender.R.File=/var/opt/novell/eDirectory/log/cef-events.log

Configuring the CEF Events for Auditing:

  1. Open iManager from a Web browser using the following URL: <https://ip_address_or_DNS/nps/iManager.html>

  2. Log in using your username and password (Admin Mode)

  3. Select Roles and Tasks. > eDirectory Auditing > Audit Configuration

  4. Select the CEF tab

  5. Configure the CEF events

    1. Do Not Send Replicated Events: Select this option to stop receiving duplicate events due to replication from other servers.

    2. Basic Events Configuration : Select all Events.

  • Individual event categories under the basic events configuration section will be collapsed by default. You can expand each category and select ALL sub-events.

  • We DO NOT recomment filtering of any Object Events and Attribute Events. Select ALL from the available list whenever presented.

  • TimeZone is always selected as UTC. No other timezone should be selected and not supported.

Integration Parameters

Parameters required from customer for Integration.

Property

Default Value

Description

IP Address

 Microfocus NetIQ eDirectory interface IP address

Hostname or IP address of the device which forwards logs to the CyberHub

  • No labels