Configuring and Monitoring Event Logs eg Enterprise v5.6
Restricted Rights Legend The information contained in this document is confidential and subject to change without notice. No part of this document may be reproduced or disclosed to others without the prior permission of eg Innovations, Inc. eg Innovations, Inc. makes no warranty of any kind with regard to the software and documentation, including, but not limited to, the implied warranties of merchantability and fitness for a particular purpose. Trademarks Microsoft Windows, Windows NT, Windows 2000, Windows 2003 and Windows 2008 are either registered trademarks or trademarks of Microsoft Corporation in United States and/or other countries. The names of actual companies and products mentioned herein may be the trademarks of their respective owners. Copyright 2012 eg Innovations, Inc. All rights reserved.
Table of Contents CONFIGURING AND MONITORING EVENT LOGS...1 1.1 CONFIGURING THE EVENTLOG SERVER FOR MONITORING THE EG ENTERPRISE...1 1.2 ADMINISTERING THE EG MANAGER TO MONITOR EVENT LOGS...3 1.3 MONITORING THE EVENT LOGS...4 CONCLUSION...5
Table of Figures Figure 1.1:Opening the Local Security Policy...1 Figure 1.2:Viewing the Properties of Audit logon events...2 Figure 1.3:Checking the boxes for Success and Failure...2 Figure 1.4: A page displaying the disabled tests that need to be configured for an Event Log server...3 Figure 1.5: Confirmation for the Newly enabled test...4
Configuring and Monitoring Event Logs Chapter 1 Configuring and Monitoring Event Logs This chapter helps you understand the following: How to administer the eg manager to monitor event logs How to monitor event logs 1.1 Configuring the eventlog server for monitoring the eg enterprise To enable the Security log events do the following steps: 1. Follow the menu sequence Start -> Setings -> Control Panel -> Administrative tools. 2. Now click on the Local security policy node in the Administrative Tools window. Figure 1.1:Opening the Local Security Policy 1
Configuring and Monitoring Event Logs 3. When the Local Security Settings window opens, expand the Local Policies node in the treestructure in the left panel of the window, and click on the Audit Policy sub-node. 4. From the list of audit policies displayed in the right panel, select Audit logon events and right-click on it to choose Properties. Figure 1.2:Viewing the Properties of Audit logon events 5. You will see two check boxes for Success and Failure in the Audit logon events Properties window. 6. Select both the check boxes and click on Apply and then click on OK to register the changes. Figure 1.3:Checking the boxes for Success and Failure 2
Configuring and Monitoring Event Logs 1.2 Administering the eg Manager to Monitor Event Logs To administer the eg manager, do the following: 1. Log into the eg administrative interface. 2. In order to enable monitoring of the event logs of servers, the eg manager provides for a special type of component, named Event Log server. If this component is already discovered, then directly proceed towards managing it using the COMPONENTS - MANAGE/UNMANAGE page (Infrastructure -> Components -> Manage/Unmanage). However, if it is yet to be discovered, then run discovery (Infrastructure -> Components -> Discover) to get it discovered or add the Eventlog server manually using the ADD/MODIFY COMPONENTS page (Infrastructure -> Components -> Add/Modify). Remember that components manually added are managed automatically. Discovered components, however, are managed using the COMPONENTS - MANAGE/UNMANAGE page. For more details on managing components, refer to the Configuring and Monitoring Web servers document. 3. By default, eg Enterprise monitors all events logged in the event log. Alternatively, you can specify the events that require monitoring by configuring the EventLog test. To configure the EventLog test, follow the menu sequence: Agents -> Tests -> Configure -> Specific. In the AGENTS - TESTS CONFIGURATION page that appears (see Figure 1.4), select Event Log to view the tests that an eg agent executes on an EventLog server. By default, only the Enabled tests will be displayed. To view all tests, click on the Disabled Tests link at the top right corner of the page. The EventLog test is disabled by default. To enable the test, select the Event Log test from the DISABLED TESTS list and click on the << button. Clicking on the Update button in Figure 1.4 will enable the selected test. Figure 1.4: A page displaying the disabled tests that need to be configured for an Event Log server 4. The following page will appear as a confirmation for the test that is enabled recently. 3
Configuring and Monitoring Event Logs Figure 1.5: Confirmation for the Newly enabled test 5. Next, sign out of the eg administrative interface. 1.3 Monitoring the Event Logs To monitor the event logs of an Event Log server, do the following: 1. Login as a monitor / supermonitor user. 2. Click on the Components option in the menu bar, and select the Servers option from the Components menu. 3. From the Components page, click on the Event Log server for which you wish to view measurements. 4
Conclusion Chapter 2 Conclusion This document has described in detail the steps for configuring and monitoring the Event logs. For details of how to administer and use the eg Enterprise suite of products, refer to the user manuals. We will be adding new measurement capabilities into the future versions of the eg Enterprise suite. If you can identify new capabilities that you would like us to incorporate in the eg Enterprise suite of products, please contact support@eginnovations.com. We look forward to your support and cooperation. Any feedback regarding this manual or any other aspects of the eg Enterprise suite can be forwarded to feedback@eginnovations.com. 5