13.07.2015 Views

Installing CA Enterprise Log Manager - CA Technologies

Installing CA Enterprise Log Manager - CA Technologies

Installing CA Enterprise Log Manager - CA Technologies

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Example: Enable Direct Collection Using the WinRMLinux<strong>Log</strong>SensorExample: Enable Direct Collection Using theWinRMLinux<strong>Log</strong>SensorYou can enable direct collection of events generated by Windows applications orthe Windows Server 2008 operating system with the WinRMLinux<strong>Log</strong>Sensor. Todo this, you create a connector on the default agent that is based on anintegration that uses the WinRMLinux<strong>Log</strong>Sensor. Many integrations use thissensor, for example, Active_Directory_Certificate_Services,Forefront_Security_for_Exchange_Server, Hyper-V, MS_OCS, and WinRM. TheMicrosoft Windows application and operating system that generate events thatcan be retrieved by the WinRMLinux<strong>Log</strong>Sensor are those for which WindowsRemote Management is enabled.Following is a partial list of products that generate events that can be collecteddirectly by the default agent on a <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> server. For eachproduct, a unique connector is used; each connector uses theWinRMLinux<strong>Log</strong>Sensor.■■■Microsoft Active Directory Certificate ServicesMicrosoft Forefront Security for Exchange ServerMicrosoft Forefront Security for SharePoint Server■ Microsoft Hyper-V Server 2008■Microsoft Office Communication Server■ Microsoft Windows Server 2008For a complete list, see the Product Integration Matrix on Support Online.This example shows how to enable direct collection of events using a connectorbased on the WinRM integration. When such a connector is deployed, it collectsevents from a Windows Server 2008 operating system event source. Collectionbegins after you configure the event sources to log events in the Windows EventViewer and enable Windows Remote Management on the server as specified inthe Connector Guide associated with this integration.To learn how to configure the Windows Server 2008 event source1. Select the Administration tab.2. Expand Event Refinement Library, expand Integrations, expandSubscription, and select WinRM.The View Integrations Details displays the sensor name,WinRMLinux<strong>Log</strong>Sensor. Supported platforms include both Windows andLinux.3. Click the Help link on the WinRM View Integration Details.The Connector Guide for Microsoft Windows Server 2008--WinRM appears.Chapter 6: Configuring Event Collection 149

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!