Event Manager for ISS SiteProtector
Date Published: December 2009
Event Manager for ISS SiteProtector allows you to collect, evaluate, and present data collected by Internet Security Systems (ISS) SiteProtector products. By detecting, alerting on, and automatically responding to critical events, Event Manager for ISS SiteProtector helps indicate, correct, and prevent possible configuration problems and external intrusions or attacks.
Event Manager for ISS SiteProtector gathers events, alerts, and other information for ISS SiteProtector products into a secure, central repository that you can monitor from a single console. Monitoring this information from a single console aids the IT team in correlating events to determine the nature of a potential security threat.
Event Manager for ISS SiteProtector highlights events that may indicate policy changes or external attacks so you can quickly take corrective or preventive actions. For example, Event Manager for ISS SiteProtector enables you to perform the following tasks:
This module for the Security Manager product improves usability and resolves several previous issues. Many of these improvements were made in direct response to suggestions from our customers. We thank you for your time and valuable input. We hope you continue to help us ensure our products meet all your needs. You can post feedback in the Security Manager forum on Qmunity, our community Web site that also includes product notifications, blogs, and the Security Manager user group.
This document outlines why you should install this module, lists any installation requirements, and identifies any known issues. We assume you are familiar with previous versions of this product.
This release supports ISS SiteProtector 2.0 Service Pack 6. You can also use Event Manager for ISS SiteProtector to monitor ISS Proventia by using the feature in ISS Proventia to export data in SiteProtector format.
Why Install This Module?
Event Manager for ISS SiteProtector provides enhanced performance, improved usability, and supports ISS Proventia when you export data in ISS SiteProtector format. This release of the module addresses a scripting issue, enabling the module to function properly with Security Manager 6.5. (ENG279121)
The following table lists additional requirements for a Windows agent monitoring ISS SiteProtector. For more information about agent requirements, see the Installation Guide for NetIQ Security Manager.
Installing This Module
Ensure you install Log Manager for ISS SiteProtector before you install and configure this module. If you install and configure this module before installing Log Manager for ISS Site Protector, rules you create do not generate alerts.
You can install this module using the Module Installer. If you are installing the module for the first time, ensure you also add a license.
You can verify successful installation of the module in the Module Installer. After the installation completes, verify the Status column indicates the module is current and the module version listed in the Installed Version column is the same as the version in the Available Version column. For more information about installing modules, see the Installation Guide for NetIQ Security Manager.
Configuring The Module
After you install the module, run the Configuration Wizard to configure the module. For more information about using the Configuration Wizard, see the User Guide for NetIQ Security Manager.
If you are using ISS Proventia and would like to monitor ISS Proventia data along with ISS SiteProtector, configure ISS Proventia to export data in SiteProtector format.
Monitoring the Product
You can monitor the product by examining product-specific views in the Control Center and Web Console. If you have Log Manager, you can also query stored log data and run reports. For more information about views and reports, see the User Guide for NetIQ Security Manager.
If you want to export events, use the information in the following table to determine which number Security Manager uses for each ISS SiteProtector field.
NetIQ Corporation strives to ensure our products provide quality solutions for your enterprise software needs. The following issues are currently being researched. If you need further assistance with any issue, please contact Technical Support.
Removal of Monitoring Guides
Since monitoring information for updated Security Manager modules is now available in the module release notes, monitoring guides have been discontinued. However, a known issue exists where Security Manager cannot remove old monitoring guides when installing updated modules. To reduce the risk of users referencing outdated monitoring guides, Security Manager now replaces the old monitoring guide in the default documentation folder with a blank monitoring guide. Monitoring guides are installed by default in the \Program Files\NetIQ Security Manager\OnePoint\Documentation\Monitoring Guides folder on the central computer, but may have been moved or copied to a different location in your environment. After installing an updated module, you should manually delete any outdated monitoring guides that were copied or moved to other folders.
Please contact us with your questions and comments. We look forward to hearing from you.
For detailed contact information, see the Support Contact Information Web site.
For interactive conversations with your peers and NetIQ experts, become an active member of Qmunity, our community Web site that offers product forums, product notifications, blogs, and user groups.
THIS DOCUMENT AND THE SOFTWARE DESCRIBED IN THIS DOCUMENT ARE FURNISHED UNDER AND ARE SUBJECT TO THE TERMS OF A LICENSE AGREEMENT OR A NON-DISCLOSURE AGREEMENT. EXCEPT AS EXPRESSLY SET FORTH IN SUCH LICENSE AGREEMENT OR NON-DISCLOSURE AGREEMENT, NETIQ CORPORATION PROVIDES THIS DOCUMENT AND THE SOFTWARE DESCRIBED IN THIS DOCUMENT "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. SOME STATES DO NOT ALLOW DISCLAIMERS OF EXPRESS OR IMPLIED WARRANTIES IN CERTAIN TRANSACTIONS; THEREFORE, THIS STATEMENT MAY NOT APPLY TO YOU.
This document and the software described in this document may not be lent, sold, or given away without the prior written permission of NetIQ Corporation, except as otherwise permitted by law. Except as expressly set forth in such license agreement or non-disclosure agreement, no part of this document or the software described in this document may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, electronic, mechanical, or otherwise, without the prior written consent of NetIQ Corporation. Some companies, names, and data in this document are used for illustration purposes and may not represent real companies, individuals, or data.
This document could include technical inaccuracies or typographical errors. Changes are periodically made to the information herein. These changes may be incorporated in new editions of this document. NetIQ Corporation may make improvements in or changes to the software described in this document at any time.
© 2009 NetIQ Corporation. All Rights Reserved.
U.S. Government Restricted Rights: If the software and documentation are being acquired by or on behalf of the U.S. Government or by a U.S. Government prime contractor or subcontractor (at any tier), in accordance with 48 C.F.R. 227.7202-4 (for Department of Defense (DOD) acquisitions) and 48 C.F.R. 2.101 and 12.212 (for non-DOD acquisitions), the government's rights in the software and documentation, including its rights to use, modify, reproduce, release, perform, display or disclose the software or documentation, will be subject in all respects to the commercial license rights and restrictions provided in the license agreement.
Check Point, FireWall-1, VPN-1, Provider-1, and SiteManager-1 are trademarks or registered trademarks of Check Point Software Technologies Ltd.
ActiveAudit, ActiveView, Aegis, AppManager, Change Administrator, Change Guardian, Compliance Suite, the cube logo design, Directory and Resource Administrator, Directory Security Administrator, Domain Migration Administrator, Exchange Administrator, File Security Administrator, Group Policy Administrator, Group Policy Guardian, Group Policy Suite, IntelliPolicy, Knowledge Scripts, NetConnect, NetIQ, the NetIQ logo, PSAudit, PSDetect, PSPasswordManager, PSSecure, Secure Configuration Manager, Security Administration Suite, Security Manager, Server Consolidator, VigilEnt, and Vivinet are trademarks or registered trademarks of NetIQ Corporation or its subsidiaries in the USA. All other company and product names mentioned are used only for identification purposes and may be trademarks or registered trademarks of their respective companies.
For purposes of clarity, any module, adapter or other similar material ("Module") is licensed under the terms and conditions of the End User License Agreement for the applicable version of the NetIQ product or software to which it relates or interoperates with, and by accessing, copying or using a Module you agree to be bound by such terms. If you do not agree to the terms of the End User License Agreement you are not authorized to use, access or copy a Module and you must destroy all copies of the Module and contact NetIQ for further instructions.