10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Event<br />

capturing<br />

and<br />

logging<br />

You<br />

can<br />

capture<br />

events<br />

<strong>for</strong><br />

logging<br />

and<br />

auditing<br />

by<br />

using<br />

the<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

event<br />

logging<br />

facility.<br />

Event<br />

logging<br />

provides<br />

a<br />

structured<br />

hierarchy<br />

<strong>for</strong><br />

gathering<br />

messages<br />

<strong>for</strong><br />

logging<br />

and<br />

auditing<br />

purposes.<br />

The<br />

event<br />

logging<br />

feature<br />

also<br />

supports<br />

the<br />

use<br />

of<br />

alternate<br />

destinations<br />

<strong>for</strong><br />

logging<br />

output,<br />

such<br />

as<br />

consoles<br />

(stdout),<br />

pipes,<br />

and<br />

remote<br />

servers.<br />

The<br />

event<br />

logging<br />

facility<br />

has<br />

many<br />

different<br />

configuration<br />

options.<br />

This<br />

chapter<br />

describes<br />

how<br />

to<br />

configure<br />

event<br />

logging<br />

to<br />

capture<br />

common<br />

events<br />

generated<br />

by<br />

<strong>WebSEAL</strong>.<br />

Be<strong>for</strong>e<br />

using<br />

this<br />

chapter,<br />

it<br />

is<br />

recommended<br />

that<br />

you<br />

read<br />

the<br />

overview<br />

of<br />

event<br />

logging<br />

in<br />

the<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

Base<br />

<strong>Administration</strong><br />

Guide.<br />

This<br />

overview<br />

provides<br />

many<br />

details<br />

on<br />

configuration<br />

options,<br />

including<br />

output<br />

destinations,<br />

that<br />

might<br />

apply<br />

to<br />

your<br />

deployment.<br />

Note:<br />

<strong>WebSEAL</strong><br />

also<br />

supports<br />

the<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

legacy<br />

auditing<br />

model.<br />

Use<br />

of<br />

this<br />

model<br />

is<br />

recommended<br />

<strong>for</strong><br />

backwards<br />

compatibility<br />

only.<br />

For<br />

more<br />

in<strong>for</strong>mation,<br />

see<br />

“Legacy<br />

auditing”<br />

on<br />

page<br />

105.<br />

Topic<br />

index:<br />

v<br />

“Event<br />

logging<br />

configuration<br />

tasks”<br />

v<br />

“Example<br />

configuration”<br />

on<br />

page<br />

99<br />

v<br />

“Configuring<br />

HTTP<br />

logging<br />

using<br />

event<br />

logging”<br />

on<br />

page<br />

100<br />

v<br />

“Authentication<br />

event<br />

log<br />

output”<br />

on<br />

page<br />

102<br />

v<br />

“Audit<br />

data<br />

in<br />

UTF-8<br />

<strong>for</strong>mat”<br />

on<br />

page<br />

104<br />

Event<br />

logging<br />

configuration<br />

tasks<br />

The<br />

following<br />

configuration<br />

tasks<br />

are<br />

required<br />

<strong>for</strong><br />

each<br />

<strong>WebSEAL</strong><br />

audit<br />

trail<br />

file:<br />

1.<br />

Enable<br />

auditing<br />

Enable<br />

the<br />

creation<br />

of<br />

audit<br />

records.<br />

2.<br />

Specify<br />

type<br />

of<br />

audit<br />

event.<br />

Supported<br />

types<br />

of<br />

audit<br />

events<br />

<strong>for</strong><br />

<strong>WebSEAL</strong>:<br />

v<br />

Authorization<br />

v<br />

Credential<br />

acquisition<br />

authentication<br />

v<br />

HTTP<br />

requests<br />

3.<br />

Specify<br />

audit<br />

file<br />

location<br />

Location<br />

on<br />

the<br />

filesystem<br />

<strong>for</strong><br />

the<br />

audit<br />

records.<br />

4.<br />

Specify<br />

audit<br />

file<br />

size<br />

Maximum<br />

size<br />

of<br />

an<br />

audit<br />

trail<br />

file.<br />

When<br />

the<br />

maximum<br />

size<br />

is<br />

reached,<br />

the<br />

file<br />

is<br />

backed<br />

up<br />

and<br />

a<br />

new<br />

file<br />

is<br />

started.<br />

5.<br />

Specify<br />

file<br />

flush<br />

interval<br />

Frequency<br />

with<br />

which<br />

the<br />

server<br />

flushes<br />

audit<br />

trail<br />

buffers<br />

to<br />

the<br />

file.<br />

The<br />

following<br />

configuration<br />

tasks<br />

are<br />

optional<br />

<strong>for</strong><br />

each<br />

<strong>WebSEAL</strong><br />

audit<br />

trail<br />

file:<br />

v<br />

Specify<br />

maximum<br />

event<br />

queue<br />

Maximum<br />

number<br />

of<br />

events<br />

to<br />

queue<br />

in<br />

memory.<br />

v<br />

Specify<br />

event<br />

queue<br />

high<br />

water<br />

mark<br />

Number<br />

of<br />

events<br />

in<br />

queue<br />

which<br />

trigger<br />

a<br />

flush<br />

from<br />

memory<br />

to<br />

file.<br />

v<br />

Specify<br />

maximum<br />

buffer<br />

size<br />

98<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!