Highlighted
Absent Member.
Absent Member.
154 views

Solaris BSM Connector to audit single directory

Does any one used Solaris BSM Syslog Connector to audit single directory on a Solaris server instead of collecting all file audit events from that Server.

Labels (1)
0 Likes
1 Reply
Highlighted
Micro Focus Expert
Micro Focus Expert

It is up to the configuration capabilities of Solaris BSM audit to audit a single directory and not the whole server. Whether or not BSM auditing can be configured for a single directory vs the entire server is a Solaris/Oracle question, not an ArcSight/HPE question. The BSM audit system is tightly integrated with the Solaris kernel.

The ArcSight connector will accept BSM audit logs regardless of one directory or entire server.

It is possible to use filtering on the connector to only deal with events for a particular directory, but that is probably not what you want to do.

0 Likes
The opinions expressed above are the personal opinions of the authors, not of Micro Focus. By using this site, you accept the Terms of Use and Rules of Participation. Certain versions of content ("Material") accessible here may contain branding from Hewlett-Packard Company (now HP Inc.) and Hewlett Packard Enterprise Company. As of September 1, 2017, the Material is now offered by Micro Focus, a separately owned and operated company. Any reference to the HP and Hewlett Packard Enterprise/HPE marks is historical in nature, and the HP and Hewlett Packard Enterprise/HPE marks are the property of their respective owners.