Imperva Cyber Community

communities_1.jpg
 View Only
Expand all | Collapse all

Is there a centralized logging location for DSF / Sonar Hub system (and other) changes and how to extract them.

  • 1.  Is there a centralized logging location for DSF / Sonar Hub system (and other) changes and how to extract them.

    Posted 11 days ago

    Where does data security fabric (DSF/ Sonar) log for example: 

    • changes to system critical functions / configurations, 
    • changes in policies of any type,
    • changes in workflow,
    • changes in access / authorizations. 

    We know exactly where this listed or presented to us in DAM and we can setup action sets to send these alerts to our SIEM, so where is this available in DSF?
    I'm aware of things like Monitoring Audit Policy History, which shows me the history but I'm asking about instant notification of changes.  Events and alerts written to an audit.log file etc.


    #DatabaseActivityMonitoring
    #jSonar

    ------------------------------
    Albert Wong
    Sr Security Engineer
    Mufg Union Bank, National Association
    San Francisco CA
    ------------------------------


  • 2.  RE: Is there a centralized logging location for DSF / Sonar Hub system (and other) changes and how to extract them.

    Posted 6 days ago

    https://docs.imperva.com/bundle/v4.19-sonar-admin-guide/page/80197.htm

    Please see this link to stream the data from DSF Hub to your SIEM.



    ------------------------------
    Nikhil Maini
    ------------------------------