|
Event File Collector |
Previous
Next
|
|
Event File Collector Monitor Items collect Event Log Files (.EVT and .EVTX) from the Agents being monitored. The Event File Collector operates at a scheduled interval (the default is every 24 hours). At each interval, the Event File Collector will attempt to copy and store the specified Event Log Files from the assigned Agents. The files will be stored by default under the ELM Enterprise Manager installation folder in a sub-directory named EVT Files. This location can be modified on the Behavior tab of the Event File Collector properties. Log Selection Displays the Available Logs and Selected Logs the Collector is configured to copy and store. By default, the list of Selected Logs contains an asterisk, so the Monitor will collect all log files possible. Specific logs can replace the asterisk to collect a subset of log files. Use the Add and Remove buttons to move selected logs between the Available Logs and Selected Logs lists. To list logs from another system, click the Choose log source button and enter or select a computer name. If you know the name of a log, you can enter it in the Enter a log name field, and click the Add button. All events may be cleared from the selected logs after collection by checking the box labeled Clear Logs after collection. Note Behavior This tab configures where an how to store collected log files.
A cryptographic hash may be created for collected log files to help verify the log file remains unchanged. Note that both the collected log file and the hash file should be secured from tampering.
ELM includes a tool to help verify hashed files. Right-click on the ELM Server and select Tools | Verify Evt Files to launch the tool.
The hash value for a collected file can also be calculated with the Microsoft File Checksum Integrity Verifier tool. Please see Microsoft Knowledge Base article 841290 for more details. Actions
Additionally, the Event File Collector may create one or more of the following events:
Categories Displays the Agent Categories to which the Monitor is assigned. Click to select or deselect Agent Categories. Right click to create or edit Agent Categories. Test Monitor Test any Monitor Item against any Agent capable of running the Item using the drop-down and Test button on this dialog box. Testing a Monitor Item prior to putting it into production validates that the monitor item is configured properly. To test a monitor item:
If the test was successful, you will receive a pop-up indicating this and the option to see detailed results of the test. If the test failed, detailed results of the test will automatically open in Notepad. Schedule Displays the Scheduled Interval and Scheduled Hours settings which control the frequency for the Monitor Item. Scheduled Interval tab Specify the interval at which the monitoring, polling or action is to occur. Depending on the Monitor Item type, Items can be scheduled in interval increments of Seconds, Minutes, Hours and Days. The Scheduled Interval is relative to the top of the hour or top of the minute. For example, if a Scheduled Interval is configured for 10 minutes, the Monitor Item will execute at hh:10:00, hh:20:00, hh:30:00, hh:40:00, hh:50:00, hh:00:00, etc. If a Scheduled Interval is configured for 15 seconds, the Monitor Item will execute at hh:00:15, hh:00:30, hh:00:45, hh:00:00, hh:01:15, etc. Scheduled Hours tab Select the days and/or hours this item is active. By default, the schedule is set to ON for all hours and all days. Mouse clicks toggle squares between ON and OFF. Clicking on an individual square will toggle the active schedule for that hour. Clicking on an hour at the top of the grid, or on a day of the week at the left of the grid will toggle the corresponding column or row. Keyboard equivalents are the arrow keys and the space bar. Properties Tab This read-only tab displays the properties of the selected object and the values for those properties.
|