Ibm Aix
Ibm Aix
IBM AIX
Last Modified: Thursday, November 2, 2017
Note: RSA is qualifying support for the major version. In case of any configuration changes
or logs not parsing in a minor version, please open a case and we will add support for it.
2. To log all messages of debug level and higher to the RSA NetWitness Suite, add the
following lines:
l auth.debug @xxx.xxx.xxx.xxx
l daemon.debug @xxx.xxx.xxx.xxx
l kern.debug @xxx.xxx.xxx.xxx
l user.debug @xxx.xxx.xxx.xxx
where xxx.xxx.xxx.xxx is the IP address of the RSA NetWitness Log Decoder or
Remote Log Collector.
Warning: Do not use the -n flag when starting the syslogd daemon. This flag suppresses
logging of priority and facility information for each log message. If this flag is used, RSA
NetWitness Suite cannot recognize AIX messages.
Note: This step is optional. Only perform these tasks if you want to track the changes
to the syslog.conf file.
2. To log all messages from the syslog.conf file, add the following lines:
*.debug @xxx.xxx.xxx.xxx
w = "SYSLOG_WRITE"
Note: The tag "SYSLOG_WRITE" must be copied exactly. No other tags will be
parsed.
binmode = off
streammode = on
cmds = /etc/security/audit/streamcmds
SYSLOG_WRITE
d. In the Users section, define the users to monitor for the audit events. For
example,
root = general
name = general
/audit/stream.out &
/usr/sbin/audit start
/usr/sbin/audit query
a. After the query runs, at the beginning of the output, confirm this line.
auditing on
bin processing off
/etc/syslog.conf
w = SYSLOG_WRITE
refresh -s syslogd
9. If you do not observe logs in real time, you must shut down the audit system and start
it again by running these commands.
/usr/sbin/audit shutdown
/usr/sbin/audit start
refresh -s syslogd
2. In the Services grid, select a Log Decoder, and from the Actions menu, choose View
> Config.
3. In the Service Parsers Configuration panel, search for your event source, and ensure
that the Config Value field for your event source is selected.
Note: You only need to configure Syslog collection the first time that you set up an event
source that uses Syslog to send its output to NetWitness.
You should configure either the Log Decoder or the Remote Log Collector for Syslog. You
do not need to configure both.
2. In the Services grid, select a Log Decoder, and from the Actions menu, choose View
> System.
2. In the Services grid, select a Remote Log Collector, and from the Actions menu,
choose View > Config > Event Sources.
5. Select either syslog-tcp or syslog-udp. You can set up either or both, depending on
the needs of your organization.
6. Select the new type in the Event Categories panel and click + in the Sources panel
toolbar.
The Add Source dialog is displayed.
7. Enter 514 for the port, and select Enabled. Optionally, configure any of the
Advanced parameters as necessary.
Click OK to accept your changes and close the dialog box.
Once you configure one or both syslog types, the Log Decoder or Remote Log Collector
collects those types of messages from all available event sources. So, you can continue
to add Syslog event sources to your system without needing to do any further
configuration in NetWitness.
Trademarks
RSA, the RSA Logo and EMC are either registered trademarks or trademarks of EMC Corporation
in the United States and/or other countries. All other trademarks used herein are the property of
their respective owners.