13.07.2015 Views

Installing CA Enterprise Log Manager - CA Technologies

Installing CA Enterprise Log Manager - CA Technologies

Installing CA Enterprise Log Manager - CA Technologies

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Configuring the Event <strong>Log</strong> StoreAbout Local FiltersLocal filters operate on a live report as you view it and temporarily override theglobal settings. You can use local filters to refine the data in a report to help youresolve security incidents or to find a specific report in a list of generated reports.The local configuration tasks include the following:■■Set a new filter for a live report while you are viewing itSet a filter in a list of generated reports to see a subset of the list by time andreport typeThe online help has more information about setting local filters while viewing areport or a list of reports.Configuring the Event <strong>Log</strong> StoreThe event log store is the underlying proprietary database that contains collectedevent logs. The configuration options you set for the event log store service canbe global or local, and affect the <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> servers' storage andarchival of events. The process for configuring the event log store includes thefollowing:■■■Understand the event log store serviceUnderstand how the event log store handles archive filesConfigure the event log store's global and local valuesThis includes setting database size, basic archive file retention values,summarization rules for aggregating similar events, suppression rules toprevent specific events from being stored in the database, federationrelationships, and auto-archive options.<strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> automatically closes active database files and createsarchive files when the active databases reach the capacity you define for thisservice. Then <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> opens new, active files to continueevent logging operations. You can set auto-archive options for handling thesefiles, but only as a local configuration for each <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> server.116 Implementation Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!