This cool solution is to help the users configure the eDirectory instrumentation (available with eDirectory 8.8 SP5) with the new Sentinel Platform Agent.
Install eDirectory Instrumentation: The steps for installing and un-installing eDirectory instrumentation can be found here.
Understanding the Log Schema (LSC) file: The Log Schema file defines the framework for logging information. LSC file contains information like, Event IDs, Group IDs, Event Description, etc.
The Sentinel Server uses log schemas to create localized, human-readable log files.
Following is the schema for each event:
EventID, Description, Originator Title, Target Title, SubTarget Title, Text1 Title, Text2 Title, Text3 Title, Value1 Title, Value1 Type, Value2 Title, Value2 Type, Value3 Title, Value3 Type, Group Title, Group Type, Data Title, Data Type, Display Schema
The Log Schema file for the eDirectory instrumentation is the edir_en.lsc file, which is bundled with the eDirectory instrumentation package on all the platforms.
Sample from the edir_en.lsc file:
000B0001,Create Object,Perpetrator,Object DN,Class,,,Tree Name,,,,,,,Transaction Number,N,,,[$rC] [$SO]: A new eDirectory object called $SU (Class: $SY) was created by $SB\r\n 000B0002,Delete Object,Perpetrator,Object DN,Class,,,Tree Name,,,,,,,Transaction Number,N,,,[$rC] [$SO]: Object $SU (Class: $SY) was deleted by $SB\r\n 000B0003,Rename Object,Perpetrator,Object DN,New Object DN,,Class,Tree Name,,,,,,,Transaction Number,N,,,[$rC] [$SO]: Object $SU (Class: $ST) was renamed to $SY by $SB\r\n
More information on the LSC files can be found at: http://developer.novell.com/documentation/novlaudit/novaudit/data/brg0waf.html#brg0ygf
#ndssch -t MY-TREE admin.org /opt/novell/eDirectory/lib/nds-schema/ediraudit.sch #ice -S SCH -f /opt/novell/eDirectory/lib/nds-schema/ediraudit.sch -D LDAP -s
-d cn=admin,o=org -w password
Note: To automatically load eDirectory instrumentation every time eDirectory is started, add the following line in /etc/opt/novell/eDirectory/conf/ndsmodules.conf
auditds auto #eDirectory Instrumentation
Note: To automatically load eDirectory instrumentation every time eDirectory is started, click on nauditdls.dlm and then click Startup. Enable the Automatic option by clearing the check box and click OK..
|Not able to view the events from the Sentinel Platform Agent Log File present in the default location.||Check the eDirInst.properties file for the location of the file, as it could have been customized.|
|Not able to see the eDirectory events||
Disclaimer: As with everything else at NetIQ Cool Solutions, this content is definitely not supported by NetIQ, so Customer Support will not be able to help you if it has any adverse effect on your environment. It just worked for at least one person, and perhaps it will be useful for you too. Be sure to test in a non-production environment.