13.07.2015 Views

Installing CA Enterprise Log Manager - CA Technologies

Installing CA Enterprise Log Manager - CA Technologies

Installing CA Enterprise Log Manager - CA Technologies

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Agent PlanningMore than one syslog event source can transmit events through a singleconnector, since the listener receives all of the traffic on a specified port. <strong>CA</strong><strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> can listen for syslog events on any port. (If you arerunning an agent as a non-root user there may be restrictions on the use of portslower than port 1024.) The standard ports may be receiving an event streamcomposed of many different types of syslog events. These might include UNIX,Linux, Snort, Solaris, CiscoPIX, Check Point Firewall 1, and others. <strong>CA</strong> <strong>Enterprise</strong><strong>Log</strong> <strong>Manager</strong> handles syslog events using listeners which are a specialized typeof integration component. You build syslog connectors based on listeners andintegrations:■■The listener provides the connection information such as ports or trustedhosts.The integration defines the message parsing (XMP) and data mapping (DM)files.Because a single syslog connector may receive events from many event sources,you should consider whether to route syslog events based on their type orsource. The size and complexity of your environment determine how you balanceyour syslog event reception:Many syslog types : 1 ConnectorIf a single connector has to process events from different syslog sources, andevent volume is high, the connector has to parse through all of the appliedintegrations (XMP files) until it finds a match for an event. This can causeslower performance because there is much more processing to do. However,if event volume is not too high, a single connector on the default agent maybe enough to collect all of the required events for storage.1 syslog type : 1 ConnectorIf you configure a series of single connectors to process events from a singlesyslog type, you can lighten the processing load by spreading it acrossseveral connectors. However, having too many connectors running on asingle agent can also degrade performance, as each is a separate instancerequiring individual processing.Some syslog types : 1 ConnectorIf your environment has a heavier event volume for certain types of syslogevents, you may want to configure a connector to collect only that type. Youcould then configure one or more other connectors to collect more than onesyslog event types that have a lighter event volume in your environment. Inthis way, you can balance the syslog event collection load across a smallernumber of connectors ensuring better performance.You should not necessarily need to create your own syslog listeners, though youcan do so if necessary. You could create separate syslog listeners with differentdefault values for ports, trusted hosts, and so forth. This can help to simplify thecreation of connectors if you have many connectors to create for each type ofsyslog event, for example.Chapter 2: Planning Your Environment 55

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!