Resolution
How do I configure or customize VigilEnt Security Agent for NetWare to look for particular threats?
fact
VigilEnt Security Agent for Netware 1.X
fix
VigilEnt Security Agent for NetWare (VSAN) extracts critical messages from SYS:SYSTEM\SYS$LOG.ERR
and SYS:SYSTEM\BOOT$LOG.ERR
using a technique called "log scrubbing". The log scrubbing mechanism compares the error log with words, phrases, or regular expressions that are listed in the log scrubber configuration files. If the log scrubber finds a match, the entry from the error log appears on a VSAN report. By default, VSAN extracts all messages from the boot log and selected messages from the system log, but the logs can be checked for any key words, phrases, or expressions that an administrator wants to view.
Follow the steps below to edit the log scrubber configuration files.
- Using Microsoft Windows Explorer, navigate to the
VSAN\NWAgent
directory. - If you want to edit boot messages, locate the
bootlog.pol
file.
If you want to edit system messages, locate thesyslog.pol
file. - Open one of the above configuration files in a text editor.
- Scroll-down to the end of the file and select the first empty line.
- Enter the words, phrases, or expressions for the log scrubber to match in the log. For example, to see all of the entries in the log that contain the word ?error,? add the word error to the first blank line at the end of the configuration file. (Each entry must appear on its own line.)
- Save the file and Exit the text editor. The error log scrubber will use the edited configuration files the next time VSAN is run.
- After running VSAN, view the reports from the VigilEnt Security Manager console or use the following information to locate the specific report to view:
boot messages
VSAN\Reports\nwrbootmsg.htm
system messagesVSAN\Reports\nwrselerr.htmvv