18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 19: Auditing and Reporting<br />

Formatting & exporting audit data for use with external tools<br />

Using <strong>Sidewinder</strong> <strong>G2</strong> formatting and exporting tools<br />

You initiate the formatting and exporting process on the <strong>Sidewinder</strong> <strong>G2</strong> using<br />

acat or the <strong>Sidewinder</strong> export utility (cf export). These tools allow you to<br />

format raw audit data collected by the <strong>Sidewinder</strong> <strong>G2</strong> into SEF, WELF, HTTP,<br />

Squid, or generic (gen) files.<br />

Using acat<br />

acat converts data, but does not export it. To format <strong>Sidewinder</strong> <strong>G2</strong> audit data<br />

using acat, follow the steps below.<br />

1 Using a command line session, log into the <strong>Sidewinder</strong> <strong>G2</strong> and type the<br />

following command to switch to the admn role:<br />

srole<br />

2 Change directories so that your present working directory (pwd) is where<br />

you want the converted files saved.<br />

3 To convert your logs to an exportable format and save them to a file, enter<br />

the following command:<br />

acat -X /var/log/auditfile > filename.format<br />

where<br />

• -X indicates the new format. Use -X for SEF, -H for W3C, and<br />

-W for Webtrends. Note that all <strong>of</strong> these arguments are capital letters.<br />

• auditfile is the log file to convert.<br />

• filename.format is the new file name and format, such as<br />

audit012006.sef. Formats include sef, http, wt, squid, and gen.<br />

For example:<br />

acat -X /var/log/audit.raw.2006...CST.gz > audit.sef<br />

converts the existing audit file into the SEF format and saves it to a file<br />

named audit.sef.<br />

The specified file is now converted and ready to be manually exported via FTP<br />

or another method.<br />

Using cf export<br />

The cf export utility both converts and exports the specified log files to a<br />

destination host you specify. This utility can also be used to create a cron job<br />

that automatically initiates an FTP export program once every 24 hours. The<br />

FTP export program uses FTP to transfer the export files from the <strong>Sidewinder</strong><br />

<strong>G2</strong> to the host you specify. The host can be on a trusted network protected by<br />

the <strong>Sidewinder</strong> <strong>G2</strong>, or it can be a host that resides somewhere on the Internet.<br />

561

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!