13.07.2015 Views

Installing CA Enterprise Log Manager - CA Technologies

Installing CA Enterprise Log Manager - CA Technologies

Installing CA Enterprise Log Manager - CA Technologies

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

How to Modify <strong>CA</strong> Audit Policies to Send Events to <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong>4. Select the EnableListener check box and set the SapiPort value to a valuethat matches what <strong>CA</strong> Audit uses.The default <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> value, 0, uses the Portmapper serviceto map the ports. If you have a port defined in <strong>CA</strong> Audit, use that settinghere.5. Accept the other field defaults, and scroll down to the list of Mapping Files.If you select the Register check box, specify a SAPI port value.6. Add the Access Control mapping file entry if it is not present, and remove theother mapping file selections from the list of Selected mapping files.7. Click Save.Modify an Existing <strong>CA</strong> Audit Policy to Send Events to <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong>Use this procedure to enable a <strong>CA</strong> Audit client to send events to both <strong>CA</strong><strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> and the <strong>CA</strong> Audit collector database. By adding a newtarget to the Route or Collector actions on an existing rule, you can sendcollected events to both systems. As an alternative, you can also modify specificpolicies or rules to send events only to the <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> server.<strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> collects events from <strong>CA</strong> Audit clients using the <strong>CA</strong>Audit SAPI Router and <strong>CA</strong> Audit SAPI Collector listeners. (<strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong><strong>Manager</strong> can also collect events using the iTech plugin directly, if you configuredany iRecorders to send directly to the <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> server.)Collected events are stored in the <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> event log storeonly after you push the policy to the clients and it becomes active.Appendix B: Considerations for <strong>CA</strong> Access Control Users 197

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!