About the Device
eDirectory is the foundation for the world's largest identity management deployments and is a high-end directory service that allows businesses to manage identities and security access for employees, customers, and partners. With eDirectory, businesses lay the groundwork for secure identity management solutions and multi-platform network services. eDirectory provides centralized identity management, infrastructure, Net-wide security and scalability to all types of applications running behind and beyond the firewall.
Device Information
Entity | Particulars |
---|---|
Vendor Name | Microfocus |
Product Name | NetIQ eDirectory |
Type of Device | Hosted |
Collection Method
Log Type | Ingestion label | Preferred Logging Protocol - Format | Log collection method |
---|---|---|---|
NetIQ eDirectory | NETIQ_EDIRECTORY | Syslog - CEF | CyberHub |
Port Requirements
Source | Destination | Port |
---|---|---|
Microfocus NetIQ eDirectory | CyberHub | 6514 (TCP) |
Device Configuration
Pre-requisites :
Configuring CEF Package : The eDirectory installation kit includes both a Linux and a Windows CEF client as part of its download package. The installation program for eDirectory installs the CEF packages on your operating system.
System Requirements : NetIQ Audit iManager Plug-in requires iManager 3.1 at a minimum
Configuring the CEF Property File :
The eDirectory media includes a sample properties file, auditlogconfig.properties.template file in the configdir (n4u.server.configdir) directory.
Location of the Property File :
Operating System | Location of the Property File |
---|---|
Linux | /etc/opt/novell/eDirectory/conf/auditlogconfig.properties |
Windows | <Install Path>/novell/nds/auditlogconfig.properties |
The CEF auditlogconfig.properties file for windows contains the following information:
# Brief description for appenders and their options are provided. # For detailed decriptions refer to log4cxx documentation. # Set the level of the root logger to DEBUG and attach appenders. log4j.rootLogger=debug, S # Defines appender S to be a SyslogAppender. log4j.appender.S=org.apache.log4j.net.SyslogAppender # Defines location of Syslog server. log4j.appender.S.Host=<CyberHub IP> log4j.appender.S.Port=<port> # Specify protocol to be used (UDP/TCP/SSL). log4j.appender.S.Protocol=SSL # Specify SSL certificate file for SSL connection. # File path should be given with double backslash. log4j.appender.S.SSLCertFile=C:\\Novell\\mycert.pem # Minimum log-level allowed in syslog. log4j.appender.S.Threshold=INFO # Defines the type of facility. log4j.appender.S.Facility=USER # Defines caching for SyslogAppender. # Inputs should be yes/no log4j.appender.S.CacheEnabled=yes # Cache location directory # Directory should be available for creating cache files log4j.appender.S.CacheDir=C:\\NetIQ\\eDirectory # Cache File Size # Cache File size should be in the range of 50MB to 4000MB in limited growth mode log4j.appender.S.CacheMaxFileSize=500MB # Layout definition for appender Syslog S. log4j.appender.S.layout=org.apache.log4j.PatternLayout log4j.appender.S.layout.ConversionPattern=%c: %m%n # Defines appender R to be a Rolling File Appender. log4j.appender.R=org.apache.log4j.RollingFileAppender # Log file for appender R. # File path should be given with double backslash. log4j.appender.R.File=C:\\cef-events.log # Max size of log file for appender R. log4j.appender.R.MaxFileSize=100MB # Set the maximum number of backup files to keep for appender R. # Max can be 13. If set to zero, then there will be no backup files. log4j.appender.R.MaxBackupIndex=10 # Layout definition for appender Rolling log file R. log4j.appender.R.layout=org.apache.log4j.PatternLayout log4j.appender.R.layout.ConversionPattern=%d{MMM dd HH:mm:ss} %c %m%n
You must restart eDirectory after changing any configuration.
Replace the above Windows Commands if LINUX OS is used :
Windows | Linux |
---|---|
#log4j.appender.S.SSLCertFile=C:\\Novell\\mycert.pem | #log4j.appender.S.SSLCertFile=etc/opt/novell/mycert.pem |
#log4j.appender.S.CacheDir=C:\\NetIQ\\eDirectory | #log4j.appender.S.CacheDir=/var/opt/novell/eDirectory |
#log4j.appender.R.File=C:\\cef-events.log | #log4j.appender.R.File=/var/opt/novell/eDirectory/log/cef-events.log |
Configuring the CEF Events for Auditing:
Open iManager from a Web browser using the following URL: <https://ip_address_or_DNS/nps/iManager.html>
Log in using your username and password (Admin Mode)
Select Roles and Tasks. > eDirectory Auditing > Audit Configuration
Select the CEF tab
Configure the CEF events
Do Not Send Replicated Events: Select this option to stop receiving duplicate events due to replication from other servers.
Basic Events Configuration : Select all Events.
Individual event categories under the basic events configuration section will be collapsed by default. You can expand each category and select ALL sub-events.
We DO NOT recomment filtering of any Object Events and Attribute Events. Select ALL from the available list whenever presented.
TimeZone is always selected as UTC. No other timezone should be selected and not supported.
Integration Parameters
Parameters required from customer for Integration.
Property | Default Value | Description |
---|---|---|
IP Address | Microfocus NetIQ eDirectory interface IP address | Hostname or IP address of the device which forwards logs to the CyberHub |