FAQ's
|
|
|||
| Q1. When Windows Event Log is full, how does EventTracker™ function? | |||
| Q2. What are the ports used by EventTracker™? Since I am using a personal firewall have I to exempt these ports for EventTracker™ to work on my system? | |||
| Q3. How do I configure program exceptions in Windows Firewall Group Policy for EventTracker? | |||
Q4. What is the EventTracker™ agent? What is its function? Can I use EventTracker™ Installation kit? |
|||
| Q5. How is EventTracker™ agent used? | |||
| Q6. Why do I need an agent to monitor events? | |||
| Q7. What are the custom events generated by EventTracker™? | |||
| Q8. How do I optimize Event Tracker? Can I use filter and Traffic Analyser? | |||
| Q10. Is it possible to import existing event log files (evt format) into EventTracker™? | |||
| Q11. Can we collect event logs in a secure manner? | |||
| Q12. Does EventTracker provide a method to include multiple match strings in Filters, Alerts & Categories? | |||
| Q13. How does Agentless feature work? | |||
| Q14. How do I configure to play a sound file when I receive a certain critical event? | |||
| Q15. Can we receive events from CISCO PIX firewall into EventTracker? | |||
| Q16. What does "Duplicate Alert Suppression" mean? | |||
| Q17. How do I use the feature "Duplicate Alarm Suppression"? | |||
| Q18. Can I set different "Duplicate Alarm Suppression" per Alert? | |||
| Q19. Can I set Alerts for specific timings? | |||
| Q1. When Windows Event Log is full, how does EventTracker™ function? | |||
When any of the Windows Event Log file is full, EventTracker™ will back up the specific event log file and then clear the log file. Logging of events continues and event log monitoring never stops. Eg: Assume that the application log file (AppEvent.Evt) is full. First a back up file is created as AppEvent<Time Ticks>.Evt into the EventTracker™ Agent directory. Content of the application log file - which is full - is copied into this new file. For example, it can have a sample name as “AppEvent1035280039.evt”. ('C:\Program Files\Prism Microsystems\Tracker\Agent' is the path if default installation directory in the Agent was chosen). Then the application log file is cleared and is ready to log subsequent events. |
|||
| Q2. What are the ports used by EventTracker™? Since I am using a personal firewall I have to exempt these ports for EventTracker™ to work on my system? | |||
Ports used by Client component. Ports used by Manager component. |
|||
| Q3. How do I configure program exceptions in Windows Firewall Group Policy for EventTracker? | |||
The syntax for defining program exceptions in Windows Firewall Group policy settings is ProgramPath:Scope:Enabled|Disabled:ApplicationName The settings required to configure EventTracker as an exception are: The syntax for defining port exceptions in Windows Firewall Group policy settings is Port#:TCP|UDP:Scope:Enabled|Disabled:PortName The settings required to configure EventTracker ports are: |
|||
The EventTracker™ agent is a highly tuned agent, which monitors the events on each system in any enterprise. It consumes virtually no resources (less than 0.5 CPU and 0.0001% Network bandwidth). The agent has been carefully designed and consists of a multithreaded architecture that makes sure that all events are monitored in an optimum way and in real-time. The main functions of the EventTracker™ agent
are: |
|||
| Q5. How is EventTracker™ agent used? | |||
The EventTracker™ agent can be installed
remotely or manually in the systems. EventTracker™ agent
can be remotely installed on systems in the same domain or
on `trusted domains. If a system is outside the domain,
the EventTracker™ agent is manually installed using
EventTracker™ Installation Kit. |
|||
| Q6. Why do I need an agent to monitor events? | |||
Earlier agent less architecture did not fulfill the increasing monitoring and security needs of our customers. Without the agent, this software cannot achieve the goal of reliability, scalability, security and performance that is required to manage any enterprise. Some casual event management tool uses the agent-less architecture to poll the events and do few useful thing but it cannot provide your organization the total event management solution needed by an enterprise. Besides the Agent-less solutions requirement of polling for events not only consumes lot more Network bandwidth but also generates a significant performance load on systems which are being monitored if you want to monitor the events in real-time. |
|||
| Q7. What are the custom events generated by EventTracker™? | |||
Click Here to view the custom events generated by EventTracker™. |
|||
| Q8. How do I optimize Event Tracker? Can I use filter and Traffic Analyser? | |||
After EventTracker™ is deployed on numerous systems in a large Network it is very likely that you notice EventTracker™ receiving millions of events. Actually a majority of these events would be of little use to you. Using appropriate priority you can filter out unnecessary events to improve utility. `Filtering unnecessary events is a powerful feature based on priority configured by you. Traffic Analyser is a tool that is part of the EventTracker™ Console. It helps to find the details of the most common events and to set your order of priority. Accordingly create filters for non-essential events that are just increasing traffic but have little value. Filtering is a continuous process. Priority may vary from one system to another. Over a period of time, with your experience, priority events can be separated from non-priority events in a specific system. Repeating this process every week enables you to receive only events of value in optimizing your operations. When non-priority events are filtered out EventTracker™ functions optimally. |
|||
| Q9. Can I have EventTracker™ Agents sitting on remote systems (outside my LAN/Domain) & capable of forwarding events to a single EventTracker™ Manager located in our HQ? | |||
Yes. EventTracker™ Agents can forward
events to any system over the Internet or intranet. The following
deployment diagram will give you a better picture of a possible
deployment. |
|||
| BACK TO TOP | |||
| Q10. Is it possible to import existing event log files (evt format) into EventTracker™? | |||
Yes, events can be imported
into the EventTracker™ database. Note: This process has to be repeated from all systems from where you would like to import the log files. For Example if the EventTracker™ Manager is installed on the system JOHN_01 and there are EventTracker™ Agents installed on OLIVER_01 and THOMAS_01 then first run this from OLIVER_01 giving JOHN_01 as the manager and then repeat the process for OLIVER_01. |
|||
| BACK TO TOP | |||
| Q11. Can we collect event logs in a secure manner? | |||
Yes, you can. Please refer
to our white paper on Secure
Collection of Event Logs. |
|||
| BACK TO TOP | |||
| Q12. Does EventTracker provide a method to include multiple match strings in Filters, Alerts & Categories? | |||
Multiple string match feature
has been added into Alerts, Filters & categories. |
|||
| BACK TO TOP | |||
| Q13. How does Agentless feature work? | |||
The Agentless event monitoring
feature has been added into the EventTracker framework. This
is in addition to the Agent based monitoring. |
|||
| BACK TO TOP | |||
| Q14. How do I configure to play a sound file when I receive a certain critical event? | |||
EventTracker provides various forms of alerts, using the "Custom action" alert option you can achieve this. Configuring EventTracker to execute a WAV file when an
ERROR event occurs. To create this configuration perform
the following steps Example: "C:\Program Files\Windows Media Player\mplayer2.exe" "C:\Program Files\GetRight\sounds\all_done.wav" - Click the OK button. |
|||
| BACK TO TOP | |||
| Q15. Can we receive events from CISCO PIX firewall into EventTracker? | |||
Yes. EventTracker is designed to receive SYSLOG events as well as SNMP traps from Cisco PIX firewall. PIX Firewall can send syslog messages to EventTracker console. You can also further customize events, send an alert or generate appropriate report using extended framework provided by EventTracker. EventTracker also contains special categories (knowledge pack) to manage PIX events. Three steps to send Syslog Messages to a EventTracker Console 1. Configure syslogd to send syslog messages to EventTracker (The Configuration Guide for the Cisco Secure PIX Firewall Version describes the procedure for configuring syslogd) logging host EventTracker 192.168.1.1 logging trap errors |
|||
| BACK TO TOP | |||
| Q16. What does "Duplicate Alert Suppression" mean? | |||
EventTracker
provides the facility of generating user configurable alerts
for events received by the EventTracker. This feature is
very useful in case the user is not always available at the
Manager Console. |
|||
| BACK TO TOP | |||
| Q17. How do I use the feature "Duplicate Alarm Suppression"? | |||
The "Duplicate
Alarm Suppression" feature is not GUI driven, but has
to be configured manually. The configuration settings are
present in the evtrxer.ini. This configuration file is located
in the directory where the EventTracker is installed. Typical
example would be: "C:\Program Files\Prism Microsystems\EventTracker" |
|||
| BACK TO TOP | |||
| Q18. Can I set different "Duplicate Alarm Suppression" per Alert? | |||
Alarm suppression can be customized per alert through the "Alert based on Count" option available under Custom tab in the Alert Group Configuration console (Management Console -> Configure menu -> Configure Alerts -> Alert Groups -> Alert Group Configuration -> Custom tab), but the global settings done in Receiver config file (evtrxer.ini) takes priority over the custom settings. |
|||
| BACK TO TOP | |||
| Q21. Can I set Alerts for specific timings? | |||
Yes, through the "Time Interval" option available under Custom tab in the Alert Group Configuration console (Management Console -> Configure menu -> Configure Alerts -> Alert Groups -> Alert Group Configuration -> Custom tab). |
|||
| BACK TO TOP |