13.07.2015 Views

Installing CA Enterprise Log Manager - CA Technologies

Installing CA Enterprise Log Manager - CA Technologies

Installing CA Enterprise Log Manager - CA Technologies

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Sending <strong>CA</strong> Audit Events to <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong>To modify an existing policy rule's action to send events to <strong>CA</strong><strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong>1. <strong>Log</strong> into the Policy <strong>Manager</strong> server and access the My Policies tab in the leftpane.2. Expand the policy folder until you can see the desired policy.3. Click the policy to display its basic information in the Details pane to theright.4. Click Edit in the Details pane to add to the policy's rules. The rule wizardstarts.5. Click the Edit Actions next to the arrow for the wizard's step 3. The wizard'srule actions page displays.6. Click the Collector action in the Browse Actions pane on the left. This displaysthe Action List to the right.You can also use the Route action to create a rule to send events to a <strong>CA</strong><strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> server.7. Click New to add a new rule.8. Enter the IP address or host name of the collection <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong><strong>Manager</strong> server.For a <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> implementations with two or more servers,you can enter a different <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> host name or IP addressin the Alternate Host Name field to take advantage of 's automaticfailover feature. If the first <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> server is not available,<strong>CA</strong> Audit automatically sends events to the server named in the AlternateHost Name field.9. Enter the name of the management <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> server in theAlternate Host Name field, and then create a description for this new ruleaction.10. Clear the check box, Perform this action on remote server, if it is checked.11. Click Add to save the new rule action and then click Finish in the wizardwindow.12. Select the Rules tab in the lower right pane, and then select a rule to check.13. Click Check Policies to check the changed rule with the new actions to ensurethat it compiles properly.Make any needed modifications to the rule and ensure that it compilescorrectly before you activate it.14. Click Activate to distribute the checked policy that contains the new ruleactions you added.15. Repeat this procedure for each rule and policy with collected events you wantto send to <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong>.Appendix A: Considerations for <strong>CA</strong> Audit Users 177

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!