4.5.6 Forwarding Events from Sentinel Server to Analytics Server

If you have an existing audit server as Sentinel Server and require a graphical view of Access Manager events by using Analytics Dashboard, then you can forward the audit events from Sentinel Server to Analytics Server by using Sentinel link connector.

When Analytics Server is installed and configured, Access Manager displays the following message:

Analytics Server will be functional only when it is set as the Audit Server.

If you want to continue using Sentinel server as the audit server, then you can ignore this message. To view the graphical view of the audit events in Analytics Dashboard you can perform the following steps:

To forward the events you must perform the following:

  1. Configure Analytics Server to receive events.

    1. Log in to Access Manager Administration Console

    2. Click Devices > Analytics Server > Reports

    3. Log in to Analytics Server with the Analytics Server administrator credentials

    4. Click admin > Applications

    5. Click Launch Control Center

    6. Click Event Source Management > Live view

    7. Click on the Table tab, then click the expand symbol (+) next to Sentinel

    8. Right click Sentinel Server, then click Add Event Source Server

    9. Select Sentinel Link from the installed connectors list, then click Next

    10. Configure network settings by specifying Port Number for Event Source Server, then click Next. The default port is 1290

    11. Continue with the default configuration for Security and Auto Configuration

    12. In the General dialog box, select the Run icon

      This allows the connector to run on 1290 so that Sentinel Server can connect with Analytics Server.

    13. Click Finish

    14. Click the expand symbol (+) next to Sentinel Server and verify if the status of Sentinel Link Server All:<port number> is On

  2. Configure Sentinel Server to send events to Analytics Server.

    1. Update the latest NetIQ Access Manager Collector in Sentinel Server

    2. Log in to the Sentinel Control Center with administrator rights

    3. Click the Configuration tab to enable Configuration on the menu bar

    4. Click Configuration, then select Integrator Manager

    5. Click the Add Integrator (+) icon to configure Integrator plug-in

    6. Select the Sentinel Link Integrator from the Select Integrator drop-down list

    7. Specify a name for the integrator in the Name field

    8. Click Next

    9. In the Server Configuration dialog box, specify the Host Name as the IP address of Analytics Server

    10. Specify the port number to connect to Analytics Server

      The default port is 1290.

    11. Click Next to continue with the default configurations, then click Test configuration to verify the connection is successful.

    12. Click OK > Finish

  3. Add an Action by using Sentinel Action Manager

    1. Navigate to control center > configuration > Action Manager

    2. Click Add

    3. In the Configure Action dialog box, specify the following:

      • Action Name: any name

      • Action: Sentinel Link

      • Name: Integrator

      • Value: Select the same integrator name that you have specified in Step 2.g.

    4. Click Save

  4. In Sentinel Server, create a routing rule to enable default routing that sends events automatically to Analytics Server

    1. Log in to Sentinel Server

    2. On the main menu, click Routing

    3. Click Edit next to Forward Events To Another Sentinel System

    4. Specify the following:

      • Criteria: (((sev:[0 TO 5]) NOT st:"I" NOT st:"A" NOT st:"P") AND (evt:"NIDS\: User session was authenticated" OR evt:"NIDS\: Risk based authentication action for user" OR rv40:"002E0606" OR rv40:"002E0525" OR rv40:"002E001F" OR rv40:"002E0029" OR rv40:"002E0514" OR rv40:"002E0102" OR rv40:"002E000C"))

      • Route to the following services: All

      • Perform the following actions: Specify the action name that you specified during the configuration of Action Manager in Step 3.

    5. Click Save

    Ensure that the routing rule is enabled.