Configuring DS Auditing

If the NAAS Default Configuration Utility has been run, Event Policy Templates for Directory Services (DS) will already be present and should be used for creating more policies. Additional templates for the same service should not be created. If the default automatic configuration utility is run, start with Step 2.

  1. Create an Event Policy Template for DS.

    1. Select a container > New > Object > naasEventPolicyTemplate.

    2. Enter the Service Identifier as eDirectory.

    3. Enter the Service Version as 1.0.

    4. Select the applicable data policy types. The applicable data policies are naasUserPolicy, naasSourceMachinePolicy, and naasTargetMachinePolicy.

    5. Check Associable to All Object Types in the Schema.

    6. To generate the event list, click Read From File > type EVENTS.TXT, which is the name of the file containing the list of DS events.

      The EVENTS.TXT file is located in the SYS:\AUDIT\NAASEVENTS directory.

  2. Create one or more DS Event Policies.

    1. Select a container > New > Object > naasEventPolicy.

    2. Select an existing DS Event Policy Template.

  3. Configure the policies based on the requirements.

  4. Associate the policy to the objects that are to be audited. For more details see Associating an Audit Policy to an Object.

  5. Grant the specific Audit agent Read rights to these policies.

  6. Load the DS Shim from the server console by using the following command:

    Load sys:\system\dsshim

  7. Move on to Starting the Audit Agent.



Previous | Next