Log management tool

Use the IBM® Security Verify Directory log management tool, idslogmgmt, to implement QRadar® log integration features.

Note: You can run only one instance of idslogmgmt on an IBM Security Verify Directory instance. And, only one instance of idslogmgmt that manages the admin tools log can be run.
To implement the QRadar features, you must start the following programs:
  • IBM Security Verify Directory Integrator server.
  • The assembly lines by using the idslogmgmt wrapper.
The log management assembly lines initially read and process the parameters that are passed by the wrapper script. Next, the log management assembly lines read the Security Verify Directory instance repository file. The assembly lines determine the version of log management tool that is associated with the servers installed. For the list of servers, the ibmslapd.conf file is read and the log management settings are retrieved. The tool checks for the setting updates in the IBM Security Verify Directory instances’ configuration files in regular intervals. The default interval is 5 minutes. If IDSLMG_CHECK_INTERVAL variable is set, then the value that is set in this variable takes precedence.

After the log management configuration settings are read from the ibmslapd.conf file, the tool finds the location of logs and runs the appropriate log management activities. The activities can include managing of log disk space usage or converting the server audit log data into syslog for the consumption by QRadar.

Note: The administration server audit log data is not converted to syslog, for integration with QRadar.

When the idslogmgmt tool is run, a PID file, idslogmgmt.pid, that contains the process ID is created and updated in the <instance home>\tmp directory. The PID file helps in determining which idslogmgmt is running or stopped for am IBM Security Verify Directory instance when the status action is specified by the log management extend operation. This process applies only to instance-specific idslogmgmt execution and not in the execution in which admin tools parameters are specified.