Environment
NetIQ UNIX Agent Manager
NetIQ 7.1 UNIX Agent
NetIQ Security Manager
Situation
Security Manger UNIX agent does not correctly parse events in the HP-UX audit trail output. This causes events to be missed and not sent in for processing by the SM Centeral Computer.
Resolution
- Please apply the following Hotfixes to the UNIX Agent Manager (in the order below) *before* applying this hotfix to ensure you have the latest UNIX Agent Manager ruleset code...
- Hotfix 71934
- Apply the .um UNIX Agent Manager patch to the UNIX Agent Manager console via ' Help > Update UNIX Agent Manager '
- This will introduce a new patch into patch manager (7.1.0.6) which needs to be applied to UNIX Agents
- This will also update the default rule set to the latest code
- After applying 7.1.0.6 to the UNIX Agents, please be sure to push the updated code within the default ruleset to the UNIX systems to ensure they have the required updates.
Cause
Additional Information
Formerly known as NETIQKB72054
Detect rule set changes:
There were several changes and enhancements to the default Detect rule set in this Hotfix since Hotfix 71934. Please be sure to re-push the following updated rule sources as well as their respective rules to your UNIX systems to get the full benefit of this hotfix:
- AIX Audit source
- IRIX Audit source
- Linux Audit source
- Crontab source
- NetParam source
- Netstat source
- Basic source
- bsm source
- filesystem source
- heartbeat source
- hp_audit source
- nessus source
- oracle audit source
- sendmail source
- syslog source
- wtmp source
Feel free to contact NetIQ technical support with any questions you may have on this hotfix and it's application.