FAQ's
|
|
|||
| Q2. I am testing the EventTracker™ 6.0. How can I move the access database file from C drive to D drive? | |||
Q3. How to configure EventTracker™ to receive SYSLOG messages from my UNIX/Linux systems? |
|||
Q4. What are the different alerts generated by EventTracker™? How do they function? |
|||
| Q5. What is the difference between `UNINSTALL CLIENT’ and `REMOVE CLIENT COMPONENT’? | |||
| Q7. What is Guaranteed Event Delivery? | |||
| Q8. Under what circumstances should I transfer existing EventTracker system to a new computer? | |||
| Q9. How do I tell when someone has changed my Group Policy? | |||
| Q10. What is the necessity to move EventTracker Archives? | |||
Yes. EventTracker™ Agents can be configured
to forward events to the system hosting Tivoli Netview. To
make this configuration, perform the following. |
|||
You could move the EventTracker™ DB from your C drive to your D drive by doing the following steps
From "C:\Program Files\Prism Microsystems\Common" move the issdbv3.mdb file to the desired folder in your D drive.
From "C:\Program Files\Prism Microsystems\Common" move the ETReports.mdb file to the desired folder in your D drive.
Restart the stopped services.
|
|||
To configure your UNIX systems to forward
syslog messages to EventTracker™, do the following *.err @192.192.150.150 e> Save and close the syslog.conf file NOTE: For more information refer the syslog.conf or syslog MAN pages. Syslog configuration may be platform-dependent and it is recommended that you check the platform documentation. The following URL's will further help you identify the configuration change(s) required to forward Syslog events to EventTracker™. 1. http://www.unet.univie.ac.at/aix/cmds/aixcmds5/syslogd.htm |
|||
| Q4. What are the different alerts generated by EventTracker™? How do they function? | |||
Six types of alerts are generated after respective configuration. They are:
One example is given below. Follow the steps to use the
'Custom action' alert option to play a sound file when a
critical event is received. Click the OK button The minimum requirements are: |
|||
In EventTracker™, a client/agent can be installed from the Client Manager or can be installed manually on the remote system. A client/agent can be removed by clicking on `UNINSTALL CLIENT’. But by uninstalling a Client the events that were logged by it will not be removed from the database. Now in certain cases there maybe a requirement to remove all information (i.e. events, system info, etc...) of that client. This can be achieved using the Manager Console's `REMOVE CLIENT COMPONENTS’ option. |
|||
EventTracker™ provides two methods for archival. One method is by storing the events in the native, Windows based .evt format. The other method known as the EventVault™ stores the event data in an ODBC compatible format. EventVault™ based archival can be configured to either automatic archival or manual archival. To enable automatic archiving the user has to launch the EventVault™ Manager, choose the Configure option and check on the enable EventVault™ option and provide the destination directory and Archival frequency. Once the EventVault™ has been configured to automatically archive events then whenever the archive period is exceeded the EventVault™ automatically creates an EventBox and stores the archived event data into it. The archived data will be removed from the main database and will be available only in the archives. In addition to the above process, the EventVault™ also creates a MD5 HASH (Checksum) for each EventBox. This MD5 HASH can be used to verify the integrity of each EventBox. The integrity of each EventBox can be verified at any time, by choosing the `verify’ option after selecting an EventBox in the EventVault™ Manager. The EventVault™ regenerates the MD5 HASH and compares it with the MD5 HASH that is stored in the database. Any mismatch will indicate that the contents of the specific EventBox have been manipulated. If the EventBox is not tampered with, then the MD5's will match and will be declared as safe. For documentation, EventBox information can be exported as a text document. Click on File – save EventBox information in a text file. An existing EventBox is retrieved on the
EventVault™ Manager by selecting Options > Extract
EventBox. |
|||
| BACK TO TOP | |||
By default UDP is used to forward events from ET Agent to Receiver in the Manager with no acknowledgement. ET has added optional TCP/IP feature to ET agent starting from version 4.0.9. After each event is received at the Manager, acknowledgement is sent to Agent to assure Guaranteed Event Delivery. A queue is created at Agent to store events if receiver is not ready (server may be temporarily down). When receiver is ready, event from the queue is forwarded to the Manager and acknowledgement is received at Agent ensuring Guaranteed Event Delivery. While forwarding, if receiver goes down, transfer stops. It resumes when receiver is ready. |
|||
| BACK TO TOP | |||
When monitoring for Group Policy Changes you can watch for 2 events. The first is Event ID 612 and the second is one of the many 566/565 events that Active Directory can generate. |
|||
| BACK TO TOP |