0
votes
1
answer
4
views

How to import users from multiple Active Directory Domains?

I have 2 AD domains that I want to import users from. There may be some overlapping users between the 2 AD domains and I don't want any duplicates. Is this possible in Securonix?
2 hours ago tgulati ♦♦101
0
votes
2
answers
391
views

How do I authenticate against the AD ?

How can i set up authentication for Securonix against the AD ? what are the files that are to be updated and the process followed
4 hours ago tgulati ♦♦101
0
votes
2
answers
42
views

Auditing level best practice

Under Configure->Settings->Logging, the various modules each have eight levels of logging. The help provided under the ? is not the clearest in defining the various levels, but seems to say the order, from the most to least logging, is: All <- Trace <- Debug <- Info <- Warn <- E...
yesterday tgulati ♦♦101
0
votes
0
answers
31
views

Tom Cat Path not specified on Startup

I just recently installed Securonix and tried to start up the program by navigating to the program folder in the command prompt and then typing in the command "securonix.bat start". The output looks like the following. Calling start function... Starting MySQL Starting Tomcat The system can not find...
18 Jun, 11:21 rsheeler11
0
votes
0
answers
44
views

What are the most common installation problems encountered?

A partial list of things I've seen: 1. Java JDK not supported - Currently 1.7.0u51 works, however 1.7.0.55 fails. 2. Schema exists, but not all MySQL scripts complete( no data or upgrade file run) 3. JAVA_HOME variable not defined, or not set correctly 4. The password for the DB not specified/in...
28 May, 18:29 David Swift11
3
votes
5
answers
777
views

Can someone round up the steps to install Securonix in a nutshell ?

Would love to collect everyones quick tips from the field to install securonix
28 May, 16:48 tgulati ♦♦101
0
votes
1
answer
145
views

How to archive data in Securonix?

How can I archive data in Securonix.
17 Apr, 14:41 Praful106
0
votes
0
answers
148
views

High memory utilization on Solaris 10

Anyone experiencing high memory utilization on Solaris 10 even though not many users are using the application?
24 Feb, 02:05 rmurthy11
0
votes
1
answer
177
views

Null Pointer Exception while Correlating events

I am getting following exception while importing data. I think application is giving this exception while correlating events. Exception in thread "pool-20-thread-6" java.lang.NullPointerException at com.securonix.application.matcher.reader.FileResourceReader.correlate(FileResourceReader.java:3016) ...
10 Feb, 19:57 Praful106
0
votes
1
answer
206
views

Null Pointer Exception while Correlating events

I am getting following exception while importing data. I think application is giving this exception while correlating events. Exception in thread "pool-20-thread-6" java.lang.NullPointerException at com.securonix.application.matcher.reader.FileResourceReader.correlate(FileResourceReader.java:3016) ...
10 Feb, 19:52 Praful106
0
votes
1
answer
242
views

Null Pointer Exception while importing data

I am getting following exception while importing activity data. I verified filter and correlation rule and every thing seems to be correct. Exception in thread "pool-14-thread-8" java.null.pointerException at com.securonix.application.marcher.process.CustomIdMatcher.matchSimilarId(CustomIdMatcher.j...
10 Feb, 19:45 Praful106
0
votes
1
answer
705
views

how to assign static IP to the users

I want to assign static IP to the particular users and use for correlation.
21 Jan, 18:32 Praful106
0
votes
1
answer
378
views

Access Scanner Startup failed

I am getting an issue in Access Scanner, Tomcat fails to deploy the Profiler with the below error. Tomcat logs are given below. Dec 08, 2013 8:44:24 AM org.apache.catalina.core.AprLifecycleListener init INFO: The APR based Apache Tomcat Native library which allows optimal performance in production ...
30 Dec '13, 17:31 tgulati ♦♦101
0
votes
2
answers
286
views

Incremental import for MS SQL logs

I am trying to import logs from MS SQL Database incrementally. I have set the Increment field Name as "Date", Type as "Date" and format as "mm/dd/yyyy". But import is not happening incrementally. What is the condition field to be specified for incremental import.
26 Sep '13, 04:26 tgulati ♦♦101
0
votes
3
answers
536
views

Configuration to enable SSL for Tomcat

How do I enable SSL https in Tomcat server running on Windows Platform so that Securonix Application runs only on port 8443? And the application can be accessed by the url https://localhost:8443?
16 Sep '13, 22:35 mnair41
0
votes
1
answer
269
views

Deleting Metatdata of a resource

How to delete/remove the metadata (i.e., suspect checks,policy violations) when we delete the activity/events of a resource
16 Sep '13, 08:24 Zubair Mohammed11
0
votes
1
answer
237
views

How to delete a resource from Resources > Resources Group

Kindly let me know how to delete a resource created in the Securonix Appliance
15 Sep '13, 19:28 Praful106
0
votes
0
answers
293
views

Importing DNS Debug logs

How to format and import DNS debug logs with the below format.what is the Regex for importing domain with below format. 20130815 12:05:56 1660 PACKET UDP Rcv 212.11.196.172 c972 R Q [8081 DR NOERROR] (3)www(6)google(3)com(2)sa(0) 20130815 12:05:56 1660 PACKET UDP Snd 192.168.192.146 b0c2 R Q [8081 ...
18 Aug '13, 04:37 Zubair Mohammed11
0
votes
1
answer
666
views

Regex for URL appearing in several formats

Have a log from palo alto that has the url that is visited by the clients. The URL may appear like: http://www.google.com?aa=blah www.google.com ftp://dev.sscc.com google.com google.com/aa?aa=111 How can we parse only the domain from this for checking against TPI?
02 Aug '13, 00:45 tgulati ♦♦101
0
votes
1
answer
904
views

Exception while using WMI Connector

When I am trying to preview events using WMI Connector, the below exception occurs. 10:20:34,569 DEBUG [WmiConnector] Max events (for preview) - 100 10:20:34,569 DEBUG [WmiConnector] Reading data for Windows 10:20:34,571 DEBUG [WmiConnector] Is test (non-Prod) env? false 10:20:34,571 DEBUG [WmiConne...
25 Jul '13, 18:48 tgulati ♦♦101
0
votes
1
answer
525
views

Configuring a Static IP on Centos VM

How can I assign static IP to cent OS
25 Jul '13, 01:19 Praful106
0
votes
0
answers
1.1k
views

Connecting to Microsoft Access Database

I am trying to connect to Microsoft Access Database with below details Jdbc URL: jdbc:odbc:Driver={Microsoft Access Driver (*.mdb)};DBQ=\IPAddress\c$\Program Files (x86)\Att\att200.mdb Driver Class: sun.jdbc.odbc.JdbcOdbcDriver But the connection is Unsuccessful and the message in the log file is Co...
24 Jul '13, 05:10 Zubair Mohammed11
0
votes
1
answer
262
views

How to import events with Epoch Timeforat

I have events from my IPS device that has Epoch Unix time in the event. What format should I enter for the field when creating attributes
22 Jul '13, 10:19 rakeshp1
0
votes
0
answers
252
views

Importing eventlogs using WMI

Please list down the steps to import windows event logs using WMI.
04 Jul '13, 03:51 Zubair Mohammed11
0
votes
1
answer
277
views

Time Missing in the Activity Feed

In one of the activity feeds, I am getting only the date. There is no time present in the file. I have mapped the date to DATETIME and specified the format of the date. When I run the import, it's still giving me the Date/Time missing error. The date is in the form 26-MAR-13. The format I have speci...
14 Jun '13, 11:59 swadhwa41
0
votes
1
answer
329
views

Installation of Universal Forwarder

Can any one please list all steps to configure Universal Forwarder in Securonix?
12 Jun '13, 18:44 Praful106
0
votes
2
answers
395
views

Access Outliers assigning mail template for Access Review

How to assign email template for Access Review. when I click on Finalize/Send for Access Review the error is "Email template missing cannot generate mail". But in Configure->Email Templates option, i have an template for Access Outlier
11 Jun '13, 09:55 Zubair Mohammed11
0
votes
0
answers
313
views

Exception in email template variables

All the variable of the email template are throwing below exception. Do I need configure anything for theses variables Expression resource is undefined on line 20, column 79 in name. Quoting problematic instruction: ----------==> ${resource} [on line 20, column 77 in name] ---------- Java backtra...
11 Jun '13, 08:55 Zubair Mohammed11
0
votes
1
answer
313
views

Driver for SQL Server

For User Import, if we have to import users from SQL Server Database, what is the driver that needs to be selected from the dropdown.
05 Jun '13, 19:32 Praful106
0
votes
1
answer
337
views

Re-Correlate accounts after import

How can I re-correlate access/activity accounts after importing data?
05 Jun '13, 10:41 Praful106
posts per page153050