Security Manager for NetApp Filer

Release Notes

Date Published: May 2011



Security Manager for NetApp Filer allows you to monitor NetApp filer devices. This module provides embedded knowledge so you can proactively manage NetApp filers and identify issues before they become critical. By detecting, alerting on, and automatically responding to critical events in real-time, Security Manager for NetApp Filer helps indicate, correct, and prevent possible intrusions, attacks, and configuration problems. This module increases the security, availability, and performance of NetApp filers.

Security Manager for NetApp Filer monitors syslog messages generated by NetApp filers. Security Manager for NetApp Filer also highlights events that may indicate configuration changes or attacks, so you can quickly take corrective or preventive actions. For example, Security Manager for NetApp Filer enables you to perform the following tasks:

  • Detect misconfigurations in your NetApp filer environment
  • Back up your configuration settings using the Secure Shell (SSH) protocol
  • Identify possible attacks
  • Notify the Security Specialists notification group of serious issues
  • Monitor your environment from a single console

Security Manager for NetApp Filer also collects events from logs and stores them in secure repositories so you can archive this data, create reports for management or auditing purposes, and analyze critical events to research issues. Security Manager for NetApp Filer collects all syslog messages you configure the NetApp filer device to send.

NetIQ often makes improvements to modules in direct response to suggestions from our customers. We thank you for your time and valuable input. We hope you continue to help us ensure our products meet all your needs. You can post feedback in the Security Manager forum on Qmunity, our community Web site that also includes product notifications, blogs, and the Security Manager user group.

This document outlines why you should install this module, lists any installation requirements, and identifies any known issues.

Return to Top

Supported Products

This release supports the following products:

  • NetApp filer models FAS2020 and later

Return to Top

Why Install This Module?

Security Manager for NetApp Filer provides support for received data from monitored NetApp filer devices. The volume and type of data that Security Manager for NetApp Filer collects is determined by the configuration of the device and the policies you have created on the device.

Return to Top

System Requirements

The following table lists additional requirements for a Windows agent. For more information about agent requirements, see the Installation Guide for NetIQ Security Manager.

Category Requirement
Processor 1.5 GHz Intel Pentium III or equivalent.
Memory 40 MB minimum. The amount of memory usage varies and depends on the environment, including event rate and other factors.
Operating System All supported Windows agent platforms.
  • Ensure you have Security Manager 6.5 or later installed.
  • Ensure you have the latest version of the Security Manager Self-Monitoring module installed. This module is required for optimum functionality of the product.

Return to Top

Installing This Module

Install the module using the Module Installer utility. For more information about installing modules, see the User Guide for NetIQ Security Manager.

You can verify successful installation of the module in the Module Installer. After the installation completes, verify the Status column indicates the module is current and the module version listed in the Installed Version column is the same as the version in the Available Version column.

After you install the module, run the Configuration Wizard to configure Security Manager for NetApp Filer. For more information about using the Configuration Wizard, see the User Guide for NetIQ Security Manager.

Return to Top

NetApp Filer Event Fields Used by Security Manager

Security Manager for NetApp Filer collects various fields from the data received from monitored NetApp filer devices. Security Manager stores some of those fields in the log archive and uses some fields for generating real-time alerts or in Forensic Analysis queries.

The following table lists the NetApp Filer data fields most commonly used by Security Manager and maps those fields to the corresponding names and values used for real-time alerting, log archival, and Forensic Analysis. You can use these fields to create processing rules or Forensic Analysis queries tailored to your specific environment. For more information about creating processing rules, see the Programming Guide for NetIQ Security Manager.

Real-Time Parameter Name/Number Log Archive Field Name Forensic Analysis Column Name
$Message message Message
$Computer NetApp Filer Name
N/A common.category Data Category
N/A common.classification.type Data Classification Type
N/A analyzer.model Platform
Source classification.origin Source Name
1 action Action
2 assessment.impact.severity Severity
3 Native Classifcation
4 Target Object
5 Target Service
6 target.service.port Target Port
7 Target User
8 source.node.address.address
Source Address
Source Node
9 target.object.type Target Object Type
10 status Status
11 common.classification Event Classification
12 target.service.protocol Target Protocol

Return to Top

Contact Information

Our goal is to provide documentation that meets your needs. If you have suggestions for improvements, please email We value your input and look forward to hearing from you.

For detailed contact information, see the Support Contact Information Web site.

For interactive conversations with your peers and NetIQ experts, become an active member of Qmunity, our community Web site that offers product forums, product notifications, blogs, and product user groups.

Return to Top

Legal Notice

Return to Top