Environment
NetIQ Audit
NetIQ eDirectory
NetIQ Sentinel
NetIQ eDirectory
NetIQ Sentinel
Situation
eDirectory 8.8.6.5 (or later)
Configure eDirectory Auditing as followings:
Modified the /etc/opt/novell/eDirectory/conf/xdasconfig.properties to include the following:
log4j.rootLogger=R
log4j.appender.R.File=/var/log/novell-audit/xdas-events.log
Added the xdasauditds module to the /etc/opt/novell/eDirectory/conf/ndsmodules.conf and also manually loaded xdasauditds within ndstrace console:
ndsmodules.conf
xdasauditds auto #XDASauditds
ndstrace -c "load xdasauditds"
In iManager:
eDirectory Auditing | Audit Configuration | XDASEvents
Components: LDAP
Log Event's Large Values: Log Large Values
XDAS Events Configuration: Account Managment Events: Create Account, Query Account, Delete Account, Modify Account
Reloaded xdasauditds module or waited 3 minutes for changes to take effect
Performed create, query, delete and modifies of account (user) objects but events aren't showing in the audit file (/var/log/novell-audit/xdas-events.log
Configure eDirectory Auditing as followings:
Modified the /etc/opt/novell/eDirectory/conf/xdasconfig.properties to include the following:
log4j.rootLogger=R
log4j.appender.R.File=/var/log/novell-audit/xdas-events.log
Added the xdasauditds module to the /etc/opt/novell/eDirectory/conf/ndsmodules.conf and also manually loaded xdasauditds within ndstrace console:
ndsmodules.conf
xdasauditds auto #XDASauditds
ndstrace -c "load xdasauditds"
In iManager:
eDirectory Auditing | Audit Configuration | XDASEvents
Components: LDAP
Log Event's Large Values: Log Large Values
XDAS Events Configuration: Account Managment Events: Create Account, Query Account, Delete Account, Modify Account
Reloaded xdasauditds module or waited 3 minutes for changes to take effect
Performed create, query, delete and modifies of account (user) objects but events aren't showing in the audit file (/var/log/novell-audit/xdas-events.log
Resolution
Upgrade to:
- eDirectory to 8.8 SP7 Patch 3 (or later), and
- iManager plug-in bundle for eDirectory post 2013-June.
Then configure auditing.