How can I send Unix alerts to Security Manager but not to Vulnerability Manager? (NETIQKB48498)

  • 7748498
  • 02-Feb-2007
  • 21-Aug-2007

Resolution

goal
How can I send Unix alerts to Security Manager but not to Vulnerability Manager? 

goal
How do I stop sending Unix alerts to Vulnerability Manager?

goal
Is there a way to configure the Unix agent to send alerts only to Security Manager?

goal
How do I configure the Unix ruleset to deliver messages to only Security Manager?

fact
NetIQ Security Agent for Unix 5.5

fact
Security Manager 5.X

fact
NetIQ Vulnerability Manager 5.5

fact
VigilEnt Security Agent for Unix 5.0

cause
The default ruleset is configured to send alerts to both Vulnerability Manager and Security Manager.

fix

If you want the Unix agent to send alerts to only Security Manager, configure the ruleset to stop sending alerts to Vulnerability Manager. For more information about rulesets, see the Unix Agent Installation and Configuration Guide, which is located in the Unix agent installation kit.

To configure the ruleset:

  1. Start the Unix Manager. For more information about starting Unix Manager, see the Unix Agent Installation and Configuration Guide.
  2. In the left pane, click Rules Manager
  3. If the Unix agent uses a custom ruleset and you do not have the ruleset saved locally, retrieve the ruleset from the host by completing the following steps:
    a. On the File menu, click From Host.
    b. Select the appropriate agent computer in the Available Hosts list, and then click OK.
  4. If the Unix agent uses a custom ruleset and you have the ruleset saved locally, open the ruleset by completing the following steps:
    a. On the File menu, click Open.
    b. Browse to the ruleset, and click Open.
  5. Right-click the rule group containing rules with Vulnerability Manager alerts you want to disable.
  6. Click Edit.
  7. Click Edit Action.
  8. On the Alert tab under the Alert section, click Message.  This step clears the Message fields for highlighted rules.
  9. Click OK.
  10. Repeat Steps 3 through 9 for each rule group you want to edit.
  11. Save the ruleset.
  12. On the File menu, click Save As and save the ruleset.
  13. Active the ruleset and push it to Unix agents by completing the following steps:
    a. On the File menu, click To Host.
    b. Select one or more Unix agent computers in the Available Hosts list.
    c. Click OK to push the rule set to the selected Unix agent computers.


Additional Information

Formerly known as NETIQKB48498