Log Manager for ISS SiteProtector

Release Notes

Date Published: December 2009

 
 

 

Log Manager for ISS SiteProtector collects events from logs and stores them in secure repositories so you can archive this data, create reports for management or auditing purposes, and analyze critical events to research issues. Log Manager for ISS SiteProtector can collect all ISS data written to the ISS SiteProtector databases, or you can filter the amount of data to collect using the Configuration Wizard.

This module for the Security Manager product improves usability and resolves several previous issues. Many of these improvements were made in direct response to suggestions from our customers. We thank you for your time and valuable input. We hope you continue to help us ensure our products meet all your needs. You can post feedback in the Security Manager forum on Qmunity, our community Web site that also includes product notifications, blogs, and the Security Manager user group.

This document outlines why you should install this module, lists any installation requirements, and identifies any known issues. We assume you are familiar with previous versions of this product.

Supported Products

This release supports ISS SiteProtector 2.0 Service Pack 6. You can also use Log Manager for ISS SiteProtector to monitor ISS Proventia by using the feature in ISS Proventia to export data in SiteProtector format.

Return to Top

Why Install This Module?

Log Manager for ISS SiteProtector provides enhanced performance, improved usability, and supports ISS Proventia when you export data in ISS SiteProtector format. This release of the module addresses a scripting issue, enabling the module to function properly with Security Manager 6.5. (ENG279121)

Return to Top

System Requirements

The following table lists additional requirements for a Windows agent monitoring ISS SiteProtector. For more information about agent requirements, see the Installation Guide for NetIQ Security Manager.

Category Requirement
Processor 1.5 GHz Intel Pentium III or equivalent.
Memory 40 MB minimum. The amount of memory usage varies and depends on the environment, including event rate and other factors. Memory use for a Windows agent monitoring ISS SiteProtector could reach 256 MB or higher.
Operating System All supported Windows agent platforms.
Software
  • Ensure you have Security Manager 6.0 or later installed.
  • A Windows agent must be installed for each ISS SiteProtector product you want to monitor. Install the Windows agent on a computer that has an ODBC Database Source Name (DSN) properly configured for your environment. To ensure the DSN is properly configured, install the Windows agent on a computer running an ISS SiteProtector event collector. If you need to install the Windows agent on a separate computer, replicate a DSN from a computer running an event collector.

Return to Top

Installing This Module

You can install this module using the Module Installer. If you are installing the module for the first time, ensure you also add a license.

You can verify successful installation of the module in the Module Installer. After the installation completes, verify the Status column indicates the module is current and the module version listed in the Installed Version column is the same as the version in the Available Version column. For more information about installing modules, see the Installation Guide for NetIQ Security Manager.

Return to Top

Configuring The Module

After you install the module, run the Configuration Wizard to configure the module. For more information about using the Configuration Wizard, see the User Guide for NetIQ Security Manager.

If you are using ISS Proventia and would like to monitor ISS Proventia data along with ISS SiteProtector, configure ISS Proventia to export data in SiteProtector format.

Return to Top

Monitoring the Product

You can monitor the product by examining product-specific views in the Control Center and Web Console. You can also query stored log data and run reports. For more information about views and reports, see the User Guide for NetIQ Security Manager.

If you want to export events, use the information in the following table to determine which number Security Manager uses for each ISS SiteProtector field.

Field Number Field Name
1 Product
2 AlertTimeDate
3 SourceAddr
4 SourcePort
5 DestinationAddr
6 ObjectName
7 AlertPriority
8 Reserved
9 Reserved
10 SensorName
11 Reserved
12 UserName
13 SecChkID
14 TagName
15 Reserved
16 Reserved
17 Reserved
18 Reserved
19 Reserved
20 Reserved
21 SensorAddressInt
22 CategoryName
23 ObjectTypeDesc
24 VictimPort

Return to Top

Known Issues

NetIQ Corporation strives to ensure our products provide quality solutions for your enterprise software needs. The following issues are currently being researched. If you need further assistance with any issue, please contact Technical Support.

Removal of Monitoring Guides

Since monitoring information for updated Security Manager modules is now available in the module release notes, monitoring guides have been discontinued. However, a known issue exists where Security Manager cannot remove old monitoring guides when installing updated modules. To reduce the risk of users referencing outdated monitoring guides, Security Manager now replaces the old monitoring guide in the default documentation folder with a blank monitoring guide. Monitoring guides are installed by default in the \Program Files\NetIQ Security Manager\OnePoint\Documentation\Monitoring Guides folder on the central computer, but may have been moved or copied to a different location in your environment. After installing an updated module, you should manually delete any outdated monitoring guides that were copied or moved to other folders.

Return to Top

Contact Information

Please contact us with your questions and comments. We look forward to hearing from you.

For detailed contact information, see the Support Contact Information Web site.

For interactive conversations with your peers and NetIQ experts, become an active member of Qmunity, our community Web site that offers product forums, product notifications, blogs, and user groups.

Return to Top

Legal Notice

Return to Top