13.07.2015 Views

Installing CA Enterprise Log Manager - CA Technologies

Installing CA Enterprise Log Manager - CA Technologies

Installing CA Enterprise Log Manager - CA Technologies

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Agent PlanningAgent PlanningAgents use connectors to collect events and transport them to the <strong>CA</strong> <strong>Enterprise</strong><strong>Log</strong> <strong>Manager</strong> server. You can configure a connector on the default agent that isinstalled with the <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> server, or you can install an agenton a server or event source in your network. The decision to use external agentsis based on event volume, agent location, data filtering needs, and otherconsiderations. Planning for agent installation involves the following:■Understanding the relationships between the following components:■■Integrations and listenersAgents■■ConnectorsSizing your network to decide how many agents to installYou should install agents relatively close to the event sources from which youwant to collect event logs. Most connectors collect events from one and only oneevent source. For syslog events, a single syslog listener can receive events frommultiple event source types. An agent can control and handle event traffic frommore than one connector.About Syslog Event Collection<strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> can receive events directly from syslog sources.Syslog collection differs from the other collection methods because severaldifferent log sources can send events to <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong>simultaneously. Consider a network router and a VPN concentrator as twopossible event sources. Both can send events to <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong>directly using syslog, but the log formats and structures are different. A syslogagent can receive both kinds of events at the same time using the supplied sysloglistener.Generally speaking, event collection falls into two categories:■■<strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> listens for syslog events on configurable ports.<strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> monitors other event sources for their events, forexample, using WMI to collect Windows events.54 Implementation Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!