Limited supportBMC provides limited support for this version of the product. As a result, BMC no longer accepts comments in this space. If you encounter problems with the product version or the space, contact BMC Support.BMC recommends upgrading to the latest version of the product. To see documentation for that version, see BMC AMI Command Center for Security 6.2.

Configure Parameters tab


As an operator, you can view and edit various system global parameters that affect the appearance and performance of the system on the Configuration Parameters tab. To access the Configure Parameters tab, navigate to Messages > Config > Parms.

The following image displays a sample tab:

Click to enlarge the image.
messagesConfigParms.png

The Parms page is a standard BMC Defender Server dialog.

To edit a parameter value

  1. Click Edit , modify the parameter, and then click Commit.
  2. If you click Edit and make changes that you decide not to keep, click Reset to return them to your last saved settings.

Data is stored in the installationDirectory/config/slparms.cnf file of the system. Replace installationDirectory with the directory in which you installed the product. The default directory is C:\Program Files\BMC Software\BMC Defender.

The following parameters are supported:

Parameter

Description

Default Message Encoding

Message type of incoming messages, such as GB2312 (for Chinese systems) or other supported languages

The parameter is adjustable only on international versions of the. On English versions of the program, this value is always Western.

De-Duplicate Msg Seconds

Number of seconds in which if a duplicate message is received it is rejected

The parameter prevents duplicate messages from flooding the BMC Defender Server system. Before the message can be received again, there must be the specified number of seconds wait time.

Accepts integer values from 0 to 36,000.

The default value is 3.

Important

The message is entered into the Messages > Aux catalog for further review.

Max Non-Indexed Search

Maximum number of messages to scan if you search for a keyword or phrase that does not contain a keyword

An example of a phrase that does not contain a keyword is the number search described in the Messages > Search page (for more information, see Search Messages screen), When you search in catalog pages, this is the maximum number of records that are searched. Setting this value too high can substantially slow down the search process.

Accepts integer values from 1,000 to 1,000,000.

The default value is 100,000 records.

Msg Keyword Links

Behavior of the system when you click a keyword in a message display

Select one of the following values:

  • Disabled—Disables any search
  • Search-All—Searches all message data for the specified keyword
  • Search-Context (default)—Search the current message catalog for the specified keyword

Self-Limit Span Times

Behavior of the self-limit span time in relevant dashboard gadgets, such as the Parse-Thread gadget

Setting the value to Disabled can degrade dashboard rendering times.

The default value is Enabled.

Last Message Repeated

Behavior after receipt of Unix-style  Last Message Repeated events

When set to Auto and a Unix system generates this event, BMC Defender Server automatically repeats the last message received from the Unix system. This assists in correlation functions.

The default value is Auto.

Keep Online Indexed Days

Number of days to keep data active on the system, as an indexed part of the search engine

For data that is older than the set number of days, the CO-maint.exe program zips and moves it the ./archive directory of the system. (Archived data is kept as long as the Keep Online Archived Days setting.) The CO-maint.exe program performs the task at midnight every night. The setting provides a way to limit the number of files and disk space required to support the program.

Accepts integer values from 1 to 500.

The default value is 30 days.

Keep Online Archived Days

Number of days to keep archived files

Archived files are kept in Gzip format in the ./archive directory of the system. For archived data that is older than the set number of days, the CO-maint.exe program deletes the data at midnight every night.

Accepts integer values from 0 to 5,000.

The default value is 180 days.

Archive Filtered Data

Whether filtered data is automatically archived each night with nonfiltered data

Filtered data is kept in Gzip format in the ./archive/filt directory. For more information about the Messages > Aux page, see Messages > AUX.

The default value is No.

Catalog Directory Path

Path to the directory that contains catalog files

The value is useful if there is an expanse of catalog data that fits more conveniently on a different disk and folder, such as the F:/Catalog disk. Specify an absolute path or a pathname relative to the s-cgi directory.

The default value is ../catalogs under the BMC Defender Server installation directory.

(SPE2207) You can add any path on your computer as the value for this parameter.

Important

Changing this value requires a restart.

(Earlier than SPE2207)

Important

This value is read-only and can only be changed with the help of BMC Support.

Syslog Directory Path

Path to the directory that contains syslog files

The value is useful if there is an expanse of syslog data that fits more conveniently on a different disk and folder, such as the F:/Syslog disk. Specify an absolute path or a pathname relative to the s-cgi directory.

The default value is ../logs under the BMC Defender Server installation directory.

Important

Changing this value requires a restart.

Archive Data Path

Path to the directory that contains compressed archive files and message digests

The value is useful if there is an expanse of archive data that fits more conveniently on a different disk and folder, such as the F:/Archive disk. Specify an absolute path or a pathname relative to the s-cgi directory.

The default value is ../archive under the BMC Defender Server installation directory.

External Data Path

Path to the directory that is used by the Reports > Query tool when searching external files

The value can be any Windows path name. For more information, see the Query > Reports page.

The default value is ../external which permits you to search for files in the BMC Defender\external directory as a standard query function.

SNMP Utility Path

Works with the Device Information page, the path to the snmpget.bat file

If the net-snmp or equivalent software resides on the disk, then SNMP requests are made using that software to acquire the device system description, uptime, and other values. This assists you in identifying the device that sent a message. If the path is invalid, or does not contain an snmpget.bat file, then no SNMP capability is enabled. For more information, see the Device Information page.

The default value is ../net-snmp under the BMC Defender Server installation directory.

SNMP Read Community

Works with the Device Information page, the SNMP read community to work with the SNMP Utility Path

This is useful to identify the type of device on the system that sent a message. If SNMP is not enabled, you leave this field blank.

The default value is public.

Require Standard IP Addresses

Whether to bypass the display and check of IP addresses to accommodate textual names and IPv6 values

This switch must be set to Yes to use the advanced features of the Address Overrides page. (This menu option is also available on the Messages > Overrides > Address > Advanced page.) When this value is set, the system can display host names or other values in place of the normal IP address for the device.

The default value is Yes.

Auto-Override Agent Addresses

Whether to override addresses with the Location: keyword value generated by the BMC Defender Server agent programs

This is useful to operate in a DHCP environment. By default, the Location value of the agent is set in the agent message prefix and is the value of the %COMPUTERNAME% environmental variable on the host platform. When this value is set to Yes, IP addresses are automatically replaced by this value for BMC Defender Server agent programs, making the message independent of the IP address. For more information, see the Messages > Overrides > Address > Advanced page. This value has no effect unless the Require Standard IP Addresses switch is set to No

The default value is No.

Auto-Override Addresses Externally

Whether to override addresses with an external DLL supplied by the vendor

This value is generally set only with the advice of vendor support and professional services. See the Messages > Address > Advanced page for additional notes on this feature.

The default value is No.

Auto-Mask User Names

Whether to mask user names anywhere in the system, reports, and notifications

This is useful for implementing user privacy and removing operator bias from the system. The value affects only the display and does not affect message reception or logged content. For more information, see the Messages > Overrides > Text > Advanced page.

The default value is No.

Auto-Lookup SID Values

Whether to automatically lookup SID values encountered in Windows messages and replace the values with the user name

Set to Yes if a Windows agent program other than BMC Defender Agent for Windows is being used. The agent programs that come with BMC Defender Server automatically lookup the SID values so the value is set to No when using these agents.

For convenience, this setting is also found on the Messages > Config > Overrides > Text > Advanced page.

The default value is No.

Default Dashboard Setting

The default value is Z_Overview.

Configure Parameters screen, special notes

Important

All the settings on this screen affect all users of the system.

The Require Standard IP Address, Auto-Override Agent Addresses and Auto-Mask User Names settings are all available on other screens. The parameter screen herein provides an alternate method of setting and auditing these values from a central location. Refer to the Messages > Overrides > Address and Messages > Overrides > Text screens for more information on the functions controlled by these three parameters.

Important

The parameters on this screen affect all portions and all users of the system.

As with the other Configure screens, the changes are applied to the central operating agents of the system. Hence, caution should be exercised when making these changes so as not to affect other users that might depend upon this data.

Important

The System > Parameters screen provides a similar function to the Messages > Parameters screen, but affects system parameters only, such as the login facility, and screen colors.

This might cause some confusion to users, causing them to initially look in the wrong location for a parameter setting. As a general rule, any parameter that affects message delivery or any of the Messages or Correlation screens is available here.


 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*