Configuration Guide EMC Avamar Last Modified: Wednesday, October 02, 2013 Event Source (Device) Product Information Vendor EMC Event Source (Device) Avamar Supported Versions/Platforms 4.1, 6.0, and 7.0 RSA Product Information Supported Version RSA envision 4.0 and 4.1 Event Source (Device) Type emcavamar, 175 Collection Method Syslog, ODBC Event Source (Device) Class.Subclass Storage.Storage Content 2.0 Table Storage This document contains the following information for the EMC Avamar event source: Configuration Instructions Release Notes 20131002-155915 Release Notes 20120305-123706 EMC Avamar Configuration Instructions Note: RSA supports collection of system events through syslog or the NIC ODBC service and audit events through the NIC ODBC Service. To configure EMC Avamar, you must complete these tasks: I. Configure Collection of System Events II. Configure Collection of Audit Events Copyright 2012 EMC Corporation. All Rights Reserved.
Configure Collection of System Events Note: System events can be collected through Syslog method or ODBC service. You must choose one or the other. To configure EMC Avamar to collect system events, do one of the following: Configure Syslog collection Configure ODBC collection Configure Syslog Collection To configure EMC Avamar for syslog collection: 1. Log on to the Avamar Administrator. 2. Click Tools > Manage Profiles > New. 3. In the Profile Name field, type envision. 4. Ensure that Syslog Notification is selected, and click Next. 5. Select all event codes that your environment requires. Note: RSA envision supports all event codes. 6. Click Finish. 7. Select the envision profile that you created, and click Edit. 8. Click the Syslog Notification tab, and ensure the fields are completed as follows. Address Enter the IP address of your envision appliance. Port Ensure that the value is 514 9. Ensure that Include extended event data is selected. 10. Click OK. Configure ODBC Collection To configure EMC Avamar System Events for ODBC collection, you must complete these tasks: I. Add EMC Avamar as a data source to the NIC Collector Service II. Set Up the NIC ODBC Service 2 Configure Collection of System Events
To add EMC Avamar as a data source: 1. Follow these steps to add the PostgreSQL ODBC driver on the RSA envision appliance: a. Click Start > Programs > Administrative Tools > Data Sources (ODBC). Note: If both Data Source ODBC-32 and ODBC-64 are available, select Data Source ODBC-32. b. In the System DSN tab, click Add. c. Select PostgreSQL ANSI. Note: If the PostgreSQL driver that you want is not available, download the latest opensource files, and install the driver. d. Click Finish. 2. In the PostgreSQL ANSI ODBC Driver Setup window, complete the fields as follows. Data Source Name Type emcavamar_syslog. Description (Optional) Enter a description of the data source. Database Type mcdb. SSL Mode Disable Server Enter the EMC Avamar IP address. Port Type 5555. User Password Type viewuser1. 3. Click Test. 4. After the test has completed successfully, click Save. To set up the NIC ODBC Service in envision: 1. Log on to RSA envision with your administrator credentials. 2. Click Overview > System Configuration > Services > Device Services > Manage ODBC Service. 3. In the Manage ODBC Service window, click Add. 4. To add the EMC Avamar data source, complete the fields as follows. Data source name Type IP address User name Password Type emcavamar_syslog. From the drop-down list, select EMC Avamar_Syslog. Select Use static IP address associated with the data source name, and enter the IP address of the database location. Type viewuser1. Configure Collection of System Events 3
Verify Password Enter the password again. Interval Enter a time interval for collection. Start ODBC Service on Ensure that Start ODBC Service on Apply is selected. Apply 5. Click Apply. 4 Configure Collection of System Events
Configure Collection of Audit Events Note: EMC Avamar audit events are collected only by the NIC ODBC Service. To configure EMC Avamar audit events for ODBC collection, you must complete these tasks: I. Add EMC Avamar as a data source to the NIC Collector Service II. Set Up the NIC ODBC Service Add EMC Avamar as a Data Source to the NIC Collector Service To add EMC Avamar as a data source: 1. On the RSA envision appliance, follow these steps to add the PostgreSQL ODBC driver: a. Click Start > Programs > Administrative Tools > Data Sources (ODBC). Note: If both Data Source ODBC-32 and ODBC-64 are available, select Data Source ODBC-32. b. In the System DSN tab, click Add. c. Select PostgreSQL ANSI. Note: If the PostgreSQL driver that you want is not available, download the latest opensource files, and install the driver. d. Click Finish. 2. In the PostgreSQL ANSI ODBC Driver Setup window, complete the fields as follows. Data Source Name Type emcavamar_audit. Description (Optional) Enter a description of the data source. Database Type mcdb. SSL Mode Disable Server Enter the EMC Avamar IP address. Port Type 5555. User Password Type viewuser1. 3. Click Test. 4. After the test has completed successfully, click Save. Configure Collection of Audit Events 5
Set Up the NIC ODBC Service in RSA envision To set up the NIC ODBC Service in envision: 1. Log on to RSA envision with your administrator credentials. 2. Click Overview > System Configuration > Services > Device Services > Manage ODBC Service. 3. In the Manage ODBC Service window, click Add. 4. To add the EMC Avamar data source, complete the fields as follows. Data source name Type IP address User name Password Verify Password Interval Start ODBC Service on Apply 5. Click Apply. Type emcavamar_audit. From the drop-down list, select EMC Avamar_Audit. Select Use static IP address associated with the data source name and enter the IP address of the database location. Type viewuser1. Enter the password again. Enter a time interval for collection. Ensure that Start ODBC Service on Apply is selected. EMC Avamar Release Notes (20131002-155915) What's New in This Release RSA added support to the RSA envision platform for EMC Avamar 7.0. New and Updated Messages For complete details on new and changed messages, see the Event Source Update Help. EMC Avamar Release Notes (20120305-123706) What's New in This Release RSA added support to the RSA envision platform for EMC Avamar 6.0 and updated the event source to content 2.0. This event source uses the Storage table. Content 2.0 features new tables and improvements to the parsing of event data into variables in those new tables. For rules and reports, note the following: 6 Configure Collection of Audit Events
For factory reports, as existing event sources are converted to Content 2.0, their device-specific reports are updated to work with the new content. In some cases, class-specific reports have replaced device-specific reports. Factory correlated rules have been modified to take advantage of the improved tables, variables and parsing. Custom rules, that involve event sources updated to work with Content 2.0, need to be rewritten. Custom reports may not produce the same results as previously. For guidance on updating custom reports, see the accompanying table documentation and the RSA envision Content Inspection Tool guide. Configure Collection of Audit Events 7