OneSpan Authentication Server can be configured to monitor certain system events as they are written to the audit file. Filters must be defined to specify which events to monitor (see Filters). One or more targets must be specified to which messages are sent when the monitored event occurs (see Targets).
To enable system monitoring, select the System Monitoring Enabled box.
Filters
You must have at least one target configured before you can add a filter (see Targets).
| Field name | Description |
|---|---|
| Name | A free form name to identify this filter. |
| Target | A target defined on the Targets tab. |
| Filter condition | A list of filter conditions (see Table: Server Configuration – System Monitoring (Filter conditions)). |
| Audit Message Types | The audit message type to be monitored. |
The Filter condition section of each filter allows you to define which strings to monitor in the Field for each defined audit message types. Adding filter conditions will further narrow the audit messages that are monitored.
| Field name | Description |
|---|---|
| Field | Select a field from the drop-down list. |
| Condition | Select a condition from the drop-down list. |
| Value | Enter a value. This field does not support wildcards such as asterisks (*). |
Targets
A target defines where notifications will be sent to when a monitored event occurs. At least one target must be defined before you can add filters (see Filters). You can define as many targets as you like.
| Field name | Description |
|---|---|
| Name | The name will be used to specify the target when configuring filters. |
| Type | The target type. Possible values:
|
| From | The email address to use as sender. |
| To | The email address to send the mail to. |
| Subject | The email subject. |
| SMS | |
| Mobile | The mobile phone number to send the SMS to. |
| SNMP | |
| Host | The IP address of the SNMP host. |
| Message Type | The type of the SNMP Host. Possible values:
|
| Security Name | The user name for SNMPv3, or the community name for SNMPv2c. |
| Authentication Type | The authentication protocol to be used. If not set to None, messages sent will be signed using the selected protocol. Possible values:
|
| Secret | The passphrase used by the authentication protocol to authenticate messages. Must contain at least eight characters. |
| Privacy Type | The privacy protocol. If not set to None, messages sent will be encrypted using the selected protocol. Possible values:
|
| Secret | The passphrase used by the privacy protocol to encrypt and decrypt messages. Must contain at least eight characters. |
When you configure SNMP targets, make sure to set either the authentication type only or both authentication and privacy type for a complete trap configuration. You cannot set a privacy type without setting an authentication type.
SNMP security considerations
We strongly recommend to configure and use SNMPv3 with both authentication and privacy enabled. Use SHA-2 with a minimum key length of 256 bit (or more) for authentication, together with the AES-256 privacy protocol.
Additionally, while SNMP passphrases must be at least eight characters long, we recommend to use longer passphrases – ideally at least 16 characters – to improve security.