Log management tool
Use the IBM® Security Verify Directory log management tool, idslogmgmt, to implement QRadar® log integration features.
- IBM Security Verify Directory Integrator server.
- The assembly lines by using the idslogmgmt wrapper.
After the log management configuration settings are read from the ibmslapd.conf file, the tool finds the location of logs and runs the appropriate log management activities. The activities can include managing of log disk space usage or converting the server audit log data into syslog for the consumption by QRadar.
When the idslogmgmt tool is run, a PID file, idslogmgmt.pid, that contains the process ID is created and updated in the <instance home>\tmp directory. The PID file helps in determining which idslogmgmt is running or stopped for am IBM Security Verify Directory instance when the status action is specified by the log management extend operation. This process applies only to instance-specific idslogmgmt execution and not in the execution in which admin tools parameters are specified.