13.07.2015 Views

Installing CA Enterprise Log Manager - CA Technologies

Installing CA Enterprise Log Manager - CA Technologies

Installing CA Enterprise Log Manager - CA Technologies

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

log recordlog sensormanagement servermapping analysismeshed federationmessage parsingA log record is an individual audit record.A log sensor is an integration component designed to read from a specific logtype such as a database, syslog, file, or SNMP. <strong>Log</strong> sensors are reused. Typically,users do not create custom log sensors.The management server is a role assigned to the first <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong>server installed. This <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> server contains the repositorythat stores shared content, such as policies, for all its <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong><strong>Manager</strong>s. This server is typically the default subscription proxy. While notrecommended for most production environments, the management server canperform all roles.A mapping analysis is a step in the Mapping File wizard that lets you test andmake changes to a data mapping (DM) file. Sample events are tested against theDM file and results are validated with the CEG.A meshed federation of <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> servers is a topology thatestablishes a peer relationship between servers. In its simplest form, server 2 isa child of server 1 and server 1 is a child of server 2. A meshed pair of servershas a two-way relationship. A meshed federation can be defined such that manyservers are all peers of one another. A federated query returns results from theselected server and all its peers.Message parsing is the process of applying rules to the analysis of a raw event logto get relevant information such as timestamp, IP address, and user name.Parsing rules use character matching to locate specific event text and link it withselected values.message parsing file (XMP)A message parsing file (XMP) is an XML file associated with a specific eventsource type that applies parsing rules. Parsing rules break out relevant data in acollected raw event into name/value pairs, which are passed to the data mappingfile for further processing. This file type is used in all integrations, and inconnectors, which are based on integrations. In the case of <strong>CA</strong> Adapters, XMPfiles can also be applied at the <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> server.message parsing libraryThe message parsing library is a library that accepts events from the listenerqueues and uses regular expressions to tokenize strings into name/value pairs.Glossary 263

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!