13.07.2015 Views

Installing CA Enterprise Log Manager - CA Technologies

Installing CA Enterprise Log Manager - CA Technologies

Installing CA Enterprise Log Manager - CA Technologies

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

message parsing token (ELM)A message parsing token is a re-usable template for building the regularexpression syntax used in <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> message parsing. A tokenhas a name, a type, and a corresponding regular expression string.MIB (management information base)The MIB (management information base) for <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong>,<strong>CA</strong>-ELM.MIB, must be imported and compiled by each product that is to receivealerts in the form of SNMP traps from <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong>. The MIB showsthe origin of each numeric object identifier (OID) used in an SNMP trap messagewith a description of that data object or network element. In the MIB for SNMPtraps sent by <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong>, the textual description of each dataobject is for the associated CEG field. The MIB helps ensure that all name/valuepairs sent in an SNMP trap are correctly interpreted at the destination.module (to download)A module is a logical grouping of component updates that is made available fordownload through subscription. A module can contain binary updates, contentupdates, or both. For example, all reports make up one module, all sponsorbinary updates make up another module. <strong>CA</strong> defines what makes up eachmodule.native eventNISTobligation policyobserved eventA native event is the state or action that triggers a raw event. Native events arereceived and parsed/mapped as appropriate, then transmitted as raw or refinedevents. A failed authentication is a native event.The National Institute of Standards and Technology (NIST) is the federaltechnology agency that provides recommendations in its Special Publication800-92 Guide to Computer Security <strong>Log</strong> Management that were used as the basisfor the <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong>.An obligation policy is a policy that is created automatically when you create anaccess filter. You should not attempt to create, edit, or delete an obligation policydirectly. Instead, create, edit or delete the access filter.An observed event is an event that involves a source, a destination, and anagent, where the event is observed and recorded by an event-collection agent.ODBC and JDBC accessODBC and JDBC access to <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> event log stores supportsyour use of event data with a variety of third-party products, including customevent reporting with third-party reporting tools, event correlation withcorrelation engines, and event evaluation by intrusion and malware detectionsproducts. Systems with Windows operating systems use ODBC access; thosewith UNIX and Linux operating systems use JDBC access.264 Implementation Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!