Configuring Windows Event Log in TrueSight
This topic provides information about configuring and monitoring Windows event logs by using the TrueSight and the Central Monitoring Administration console.
On the Add Monitoring Configuration dialog, set the following preferences:
Monitoring Solution | Monitor Proile | Monitor Type |
---|---|---|
Microsoft Windows Servers | Event Log | Windows Event Log |
Windows event logs basic configuration video
Click to view a short video (4:48) of how to configure Windows event logs for monitoring.
Windows event logs advanced configuration video
Click to view a short video (7:09) of how to configure Windows event logs for monitoring.
Configuration details
On the Add Monitor Types dialog, with the Monitoring Profile set to Event Log or Operating System, and the Monitor Type set to Windows Event Log, provide the following details:
Event Log Configuration Event Log: Select this check box to enable Event Log monitoring. By default, all Windows event logs are monitored if they are registered in the Windows registry at the following location:
HKLM\SYSTEM\CurrentControlSet\Services\Eventlog
List of Event Logs: Click button to configure the event logs. | |||
Log Name | Specify the event log name for which you want to create a filter. For example, you can enter Application or System or Security or operational event logs like, Microsoft-Windows-WinRM/Operational as the log name. | ||
Forward Windows Events To Event Manager | Select this option to forward either all, or filtered or no events to the event manager.
| ||
Use File Bookmark | This field indicates whether each event log should use a checkpoint value to guarantee that no events are missed in the event that the PATROL Agent or the KM is not loaded for a period of time. | ||
List of Filters: Click button to filter the event logs. | |||
Name | Enter a unique name that represents the event filter, and follows these rules:
| ||
Description | Enter a short description of the filter you are creating. This is additional information regarding the filter and you can change the description at any time. | ||
Report/Notify | Select one of the following options, as appropriate:
| ||
Source Details | Click button to configure the source name. | ||
Name | Specify the event log source name or a regular expression. | ||
OK | Click to save the configuration. | ||
Cancel | Click to close the dialog. | ||
| |||
Use name as a regular expression | Select this check box if you specified a regular expression in the Name field. | ||
Disable case sensitivity | Select this check box to disable case sensitivity for the source filtering. You can specify whether to make filter comparisons in a case-independent manner for the source, user, category, and string options of a Windows event filter. To disable case-independent comparisons for any of the options, ensure that the corresponding Disable Case Sensitivity check box while configuring windows event monitoring is cleared. The /PSX_P4WinSrvs/PWK_PKMforMSWinOS_config/EventLogMonitoring/eventlog/EventFilters/filter/FilterDisableCase configuration variable stores information about case-sensitivity of the event filter options. This variable has five bit values, depending upon case sensitivity, one bit corresponding to each of Source, User, Category, String, and Computer name, respectively. If any bit value is 1, a case-independent filter comparison is made for the corresponding field. You can set this variable to either of the following values:
To disable case-sensitivity in the event filters, set the value of the FilterDisableCase configuration variable to 00000. | ||
Include/Exclude Source List | Select one of the following options, as appropriate:
| ||
Event Type Details | This option helps you to configure event details. | ||
Event Types to Monitor | Select one or more of the following event types to use in the filter for monitoring.
| ||
Consolidate event types when reporting |
| ||
Event ID Details | Click button to configure event ID details. | ||
Windows Event ID(s) | You can select one or more multiple IDs in the following ways:
| ||
| |||
Use Event ID as a regular expression | Select this check box if you specified a regular expression in the Windows Event ID(s) field. | ||
Include/Exclude Event ID List | Select one of the following options, as appropriate:
| ||
Event Handling | Choose how to handle your Windows events. | ||
Annotate Graph parameter with event details | Annotates the PATROL parameter graphs associated with this event filter with information about the event. You can display the annotations by placing the cursor over the graph data points. | ||
Annotate Additional Event Data | Select this check box to annotate additional event data for the event in the annotation. You can display the annotations by placing the cursor over the graph data points. Note: Restart the PATROL Agent to apply the changes. | ||
Write event details to a text parameter | Writes details about the events that occur to a parameter. Depending on which event types the filter monitors, the following parameters are used to report this data:
| ||
Use event details for a recovery action | Saves information about the event in the agent configuration variable RetainEventDescriptions so that you can use this information in recovery actions that you create. For example, if you create a recovery action that generates an e-mail when the event filter alarms, you could include the event description in the e-mail. If you don’t use recovery actions or don’t plan to use them, deselect this option to limit use of the agent database space. For more information, see Retained-event-descriptions. | ||
Report multiple events as a single event when the event occurs | Enables event consolidation under the conditions you specify. If X number of events (of any type) occur within X seconds or minutes, they are reported using one parameter. Only one datapoint is used, but the datapoint annotation contains information about each of the events that occurred. For more information on event consolidation, see Event-Type-dialog-box. To return to the default setting (not reporting multiple events as one event and not consolidating events), enter 0 as the number of times that the event occurs. By default, this value is set to 1. | ||
Time within seconds | Specify the number of seconds that must be used for reporting multiple events as a single event. By default, this value is set to 0. Maximum Value: The maximum accepted value for this field is 35791394 minutes. | ||
Enter text automatic or Filter name to Acknowledge Alarm | Specify how you want to acknowledge the alarm raised by the event filter. You can specify one of the following values:
By default, this value is set to automatic. | ||
Advanced Properties | Click this tab to specify advanced properties for events. | ||
List of Users | Click button to configure user details. | ||
---|---|---|---|
User Name | Specify the user name associated with the events that you want to monitor or exclude from monitoring. Note: When entering a user that includes special characters that are used in regular expressions, such as a dollar sign ($), a period (.), a parenthesis (), or a slash (\), you must escape each special character with a slash. For example, if the user name is $Smith, you must enter the category as \$Smith. Event log filter fails to filter events generated with user-based filters entered with a user@domain.com format. Use just the user name (e.g. Administrator) or the Domain\User format (e.g. CIVILWAR\Administrator). | ||
OK | Click to save the configuration. | ||
Cancel | Click to close the dialog. | ||
| |||
Include/Exclude User List | Select one of the following options, as appropriate:
| ||
Disable Case Sensitivity | If you select this option, the event filter makes filter comparisons in a case-independent manner. | ||
| |||
List of Categories | Click button to provide category details for the events you want to monitor. | ||
Category Name | Specify the category name associated with the events that you want to monitor or exclude from monitoring. Note: When entering a category that includes special characters that are used in regular expressions, such as a dollar sign ($), a period (.), a parenthesis (), or a slash (\), you must escape each special character with a slash. For example, if the category is $Smith, you must enter the category as \$Smith. Event log filter fails to filter events generated with user-based filters entered with a user@domain.com format. Use just the user name (e.g. Administrator) or the Domain\User format (e.g. CIVILWAR\Administrator). | ||
OK | Click to save the configuration. | ||
Cancel | Click to close the dialog. | ||
| |||
Include/Exclude Category List | Select one of the following options, as appropriate:
| ||
Disable Case Sensitivity | If you select this option, the event filter makes filter comparisons in a case-independent manner. | ||
| |||
String Details | Click button to provide string details associated with the events you want to monitor. | ||
Include String | Specify the string from event description associated with the events that you want to monitor. When entering a string that includes special characters that are used in regular expressions, such as a dollar sign ($), a period (.), a parenthesis (), or a slash (), you must escape each special character with a slash. For example, if the string is $Error, you must enter the string as \$Error. | ||
OK | Click to save the configuration. | ||
Cancel | Click to close the dialog. | ||
Exclude String | Specify the string from the event description associated with the events. When entering a string that includes special characters that are used in regular expressions, such as a dollar sign ($), a period (.), a parenthesis (), or a slash (), you must escape each special character with a slash. For example, if the string is $Error, you must enter the string as \$Error. | ||
Disable Case Sensitivity | If you select this option, the event filter makes filter comparisons in a case-independent manner. | ||
OK | Click to save the configuration. | ||
Cancel | Click to close the dialog. | ||
Close | Click this option to save your details | ||
Computer Details | Click
| ||
Computer Name | Specify the computer associated with the events that you want to monitor or exclude from monitoring. | ||
OK | Click to save the configuration. | ||
Cancel | Click to close the dialog. | ||
Include/Exclude User List | Select one of the following options, as appropriate:
| ||
Disable Case Sensitivity | Select this check box to disable case sensitivity for computer comparison. | ||
Limit Event Subscriptions To | |||
Note: Any modification made to the configuration requires PATROL Agent restart. Only 20 combinations of sources and event IDs are supported. | |||
Event Sources | Enter a comma separated list of event sources. Note: You must specify the event sources and ids based on the filters that you have configured (using the List of Filters option) for the respective event log. | ||
Event IDs | Enter comma separated list of event ids or event range. For example: 100,1000-1010,500 | ||
| |||
OK | Click to save the configuration. | ||
Cancel | Click to close the dialog. |