10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Maximum<br />

size,<br />

in<br />

bytes,<br />

of<br />

event<br />

buffer<br />

in<br />

memory<br />

to<br />

be<br />

built<br />

from<br />

individual<br />

events.<br />

v<br />

Specify<br />

file<br />

mode<br />

Binary<br />

or<br />

text.<br />

Text<br />

mode<br />

is<br />

available<br />

<strong>for</strong><br />

Windows<br />

plat<strong>for</strong>m<br />

only.<br />

The<br />

optional<br />

configuration<br />

tasks<br />

are<br />

supported<br />

by<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

event<br />

logging<br />

but<br />

not<br />

by<br />

legacy<br />

auditing.<br />

For<br />

more<br />

in<strong>for</strong>mation<br />

on<br />

these<br />

tasks,<br />

see<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

Base<br />

<strong>Administration</strong><br />

Guide.<br />

Example<br />

configuration<br />

The<br />

syntax<br />

<strong>for</strong><br />

using<br />

logcfg<br />

to<br />

configure<br />

an<br />

audit<br />

trail<br />

file<br />

is:<br />

logcfg<br />

=category:file<br />

path=file_pathname,<br />

flush_interval=seconds,\<br />

rollover_size=number,<br />

log_id=logid,<br />

queue_size=number,<br />

hi_water=number,<br />

buffer_size=number,<br />

mode={text|binary}<br />

Supported<br />

values<br />

<strong>for</strong><br />

category<br />

are:<br />

Table<br />

15.<br />

Audit<br />

event<br />

categories<br />

Audit<br />

event<br />

type<br />

Category<br />

setting<br />

Credentials<br />

acquisition<br />

authentication<br />

audit.authn<br />

Authorization<br />

audit.azn<br />

HTTP<br />

logging<br />

in<strong>for</strong>mation<br />

http<br />

HTTP<br />

request<br />

in<strong>for</strong>mation<br />

in<br />

common<br />

log<br />

<strong>for</strong>mat<br />

http.clf<br />

HTTP<br />

Referer<br />

header<br />

in<strong>for</strong>mation<br />

http.ref<br />

HTTP<br />

User<br />

Agent<br />

header<br />

in<strong>for</strong>mation<br />

http.agent<br />

The<br />

NCSA<br />

combined<br />

<strong>for</strong>mat<br />

captures<br />

HTTP<br />

request<br />

in<strong>for</strong>mation<br />

(with<br />

time<br />

stamp)<br />

and<br />

appends<br />

the<br />

quoted<br />

referer<br />

and<br />

agent<br />

strings<br />

to<br />

the<br />

standard<br />

common<br />

log<br />

<strong>for</strong>mat.<br />

http.cof<br />

For<br />

example,<br />

the<br />

following<br />

logcfg<br />

entry<br />

creates<br />

a<br />

<strong>WebSEAL</strong><br />

audit<br />

trail<br />

file<br />

that<br />

collects<br />

authentication<br />

events:<br />

logcfg<br />

=<br />

audit.authn:file<br />

path=/var/pdweb/log/audit.log,flush_interval=20,<br />

\<br />

rollover_size=2000000<br />

Note:<br />

The<br />

above<br />

example<br />

is<br />

entered<br />

as<br />

one<br />

continuous<br />

line<br />

in<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file.<br />

In<br />

this<br />

example,<br />

auditing<br />

is<br />

enabled<br />

when<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

reads<br />

the<br />

logcfg<br />

entry<br />

at<br />

startup<br />

time.<br />

The<br />

required<br />

configuration<br />

settings<br />

are<br />

provided<br />

by<br />

the<br />

following<br />

parameters:<br />

Table<br />

16.<br />

Example<br />

values<br />

<strong>for</strong><br />

required<br />

configuration<br />

settings<br />

Parameter<br />

Required<br />

setting<br />

audit.authn:file<br />

Type<br />

of<br />

audit<br />

event<br />

path=/var/pdweb/log/audit.log<br />

Audit<br />

file<br />

location<br />

rollover_size=2000000<br />

Audit<br />

file<br />

size<br />

flush_interval=20<br />

File<br />

flush<br />

interval<br />

Chapter<br />

4.<br />

Serviceability<br />

and<br />

logging<br />

99

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!