13.07.2015 Views

Installing CA Enterprise Log Manager - CA Technologies

Installing CA Enterprise Log Manager - CA Technologies

Installing CA Enterprise Log Manager - CA Technologies

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

event_categoryevent_classeventsfederation serversfilterfolderfunction mappingsglobal configurationglobal filterThe event_category is the second-level event-specific field in eventnormalization used by the CEG. It provides a further classification of events witha specific ideal_model. Event category types include Operational Security,Identity Management, Configuration Management, Resource Access, and SystemAccess.The event_class is the third-level event-specific field in event normalization usedby the CEG. It provides a further classification of events within a specificevent_category.Events in <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> are the log records generated by eachspecified event source.Federation servers are <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> servers connected to oneanother in a network for the purpose of distributing the collection of log data butaggregating the collected data for reporting. Federation servers can beconnected in a hierarchical or meshed topology. Reports of federated datainclude that from the target server as well as that from children or peers of thatserver, if any.A filter is a means by which you can restrict an event log store query.A folder is a directory path location that <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> managementserver uses to store the <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> object types. You referencefolders in scoping policies to grant or deny users the right to access a specifiedobject type.Function mappings are an optional part of a Data Mapping file for a productintegration. A function mapping is used to populate a CEG field when the neededvalue cannot be retrieved directly from the source event. All function mappingsconsist of a CEG field name, a pre-defined or class field value and the functionused to obtain or calculate the value.The global configuration is a series of settings that apply to all <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong><strong>Manager</strong> servers that use the same management server.A global filter is a set of criteria you can specify that limits what is presented in allreports. For example, a global filter of the last 7 days reports events generated inthe last seven days.Glossary 259

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!