13.07.2015 Views

Installing CA Enterprise Log Manager - CA Technologies

Installing CA Enterprise Log Manager - CA Technologies

Installing CA Enterprise Log Manager - CA Technologies

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Mapping and Parsing FilesThe process involves the following general steps:1. Create parsing files to collect event data as name-value pairs.2. Create mapping files to map the name-value pairs into the common eventgrammar.3. Create new integrations and listeners to collect data from your event source.Integrations, parsing and mapping files, and suppression and summarizationrules are covered in depth in the <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> AdministrationGuide and the online help.Mapping and Parsing FilesDuring operation, <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> reads incoming events and breaksthem up into sections in an action called parsing. There are separate messageparsing files for different devices, operating systems, applications, anddatabases. After the incoming events are parsed into name-value pairs, that datagoes through a mapping module that places the event data into the fields in thedatabase.The mapping module uses data mapping files that are built for specific eventsources similar to the message parsing files. The database schema is thecommon event grammar that is one of the central features of <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong><strong>Manager</strong>.Parsing and mapping together are the means by which data is normalized andstored in a common database regardless of event type or message format.The integration wizard and some of the <strong>CA</strong> Adapter modules require you toconfigure the mapping and parsing files that best describe the kinds of event datafor which a connector or an adapter listens. In the configuration panels wherethese controls appear, the order of the message parsing files should reflect therelative number of events received of that type. The order of the data mappingfiles should also reflect the quantity of events received from a given source.For example, if the syslog listener module for a specific <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong><strong>Manager</strong> server receives mostly Cisco PIX Firewall events, you should put theCiscoPIXFW.XMPS and CiscoPIXFW.DMS files first in each respective list.164 Implementation Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!