Windows Event Log Management Features and More
|
ELM Enterprise Manager collects critical event log data from hundreds of systems, monitors firewalls and network devices. The data collected is processed at the central ELM Server, consolidated and stored in a Microsoft SQL Server database. Information is presented through the ELM console in a granular format, empowering System Administrators and IT Managers with real-time log management.
ELM Enterprise Manager monitors more than Windows event logs. You can also monito r TCP and UDP Syslogs and SNMP Traps as well as flat files. ELM Enterprise Manager is your complete compliance and security event log management solution.
|
|
|
Dynamic Event Views 
Event Views group events that match one or more
Filters into a consolidated display for single seat administration. Each View is dynamically updated as new events occur. You can also pause the dynamic refresh to drill down into a specific event that catches your eye - a very handy feature in a busy environment.
By using Views
to organize volumes of event log information, you can quickly
diagnose problems.
ELM is pre-populated with a variety of Event Views: |
- All
Events
- Audit Failures
- Audit Messages
- ELM Events
- Errors and Warnings
- Syslog Events
To name just a few...
|
|
|
When an ELM Server receives an event, it parses it against
defined Filters to determine if it should be displayed in a View, stored to the database, or sent via a Notification Method. Filters, Views, and Rules are
completely customizable, enabling you to manage your event data in the manner
most appropriate for your organization.
You may customize any of the pre-populated Views, or create your
own custom Views to suit your specific needs. Views can
group events by any event criteria, such as Computer Name, Event Source, User
Name, Date, ...etc.).
|
Search Events 
ELM provides a powerful Event Search feature within the ELM Editor reporting tools. If you are looking for information on a specific event ID or a user account, you can now do a search right within the ELM Console.
Search on different event types including errors, warnings, informational, audit success, audit failure, critical and verbose.
Narrow down search results by Computer Name, Event ID, Source, Category, User or Message.
(This search feature is also found in the ELM Web Viewer.) |
|

|
Event Log Alarms 
The Event Alarm compares the new event against a customized Event Filter. If the event matches or fails to match the criteria the specified number of times within the specified time period, the Action is executed.
This is a convenient tool to detect the absence of a system back-up confirmation event.
Looking for more details?
Check out the ELM Help Guide pages on Event Alarm.

|
 |
|
Event Log Collector 
The Event Collector monitors all Windows event logs and when an event match to a specified Event Filter is determined, it is expanded and transferred to the ELM Server. The collected events are reliably stored in the Primary database for reporting, Filtered to create concise Views, and used to trigger a Notification. Typically, very general Filters are configured to ensure all the data is available for accurate analysis.
Looking for more details?
Check out the ELM Help Guide pages on Event Collector.

|
Event File Collector 
The Event File Collector operates to collect and store the native event log files. (.EVT and .EVTX). These files are securely stored by default in the EVT File sub-directory under the ELM Enterprise Manager installation folder. They provide an authentic source for event log management.
Looking for more details?
Check out the ELM Help Guide pages on Event File Collector.

|
Flat File Monitoring 
The File Monitor scans ASCII or plain text files or groups for files on a scheduled basis for a specified character string. When a match is found, an Action can be triggered. Commonly monitored files include:
Examples of non-circular files include:
- Microsoft ISA Server log files
- Internet Information Services log files
- SQL Server error logs
- Backup software log files
- Anti-virus software log files
- Static.html files
- User-created flat files
Looking for more details?
Check out the ELM Help Guide pages on File Monitor.
|

|
|
SNMP Alarm 
The SNMP Alarm includes a MIB browser that queries a SNMP Object ID (OID) and triggers an Action if the value is greater than, less than, or equal to a specified value. It extends the status monitoring of ELM beyond Windows systems and into SNMP supported network devices.
Looking for more details?
Check out the ELM Help Guide pages on SNMP Alarm.
|
|

|
SNMP Collector 
The SNMP Collector monitors on a scheduled basis the SNMP Object ID’s and returns the values to the ELM Server. They are stored in the Primary Database for reporting and trending.
Looking for more details?
Check out the ELM Help Guide pages on SNMP Collector.
|
|
|
SNMP Receiver 
The SNMP Receiver is configured to process SNMP Traps from network devices. These traps can be translated against stored .mibs and converted into a Windows event log format. Like Windows events, they are stored in the Primary database for reporting, Filtered to create concise Views and used to trigger a Notification. Use ELM event log management technologies monitor non-Windows systems.
SNMP Trap with OIDs shown:
Warning
TEST3
1/19/2010 7:49:13 PM
1/19/2010 7:49:13 PM
{0A282598-0136-4222-ADCC-431B9DDE30BC}
2000
SNMP
None
SPECIFIC TRAP
None
Enterprise specific trap id 0
Host Address: TEST3.tnttestlab.com (127.0.0.1)
.iso.org.dod.internet.private.enterprises.lanmanager.2.1 = TEST3
.iso.org.dod.internet.private.enterprises.lanmanager.2.2 = 0
.iso.org.dod.internet.private.enterprises.lanmanager.2.3 = Audit Success
.iso.org.dod.internet.private.enterprises.lanmanager.2.4 = Application
.iso.org.dod.internet.private.enterprises.lanmanager.2.5 = Source
.iso.org.dod.internet.private.enterprises.lanmanager.2.6 = Category
.iso.org.dod.internet.private.enterprises.lanmanager.2.7 = Username
.iso.org.dod.internet.private.enterprises.lanmanager.2.8 = This is a test event message.
SNMP Trap without OIDs Shown:
Warning
TEST3
1/19/2010 7:49:41 PM
1/19/2010 7:49:41 PM
{30202DE3-57EB-4B93-B63A-4DB9408A972A}
2000
SNMP
None
SPECIFIC TRAP
None
Enterprise specific trap id 0
Host Address: TEST3.tnttestlab.com (127.0.0.1)
TEST3
0
Audit Success
Application
Source
Category
Username
This is a test event message.
Looking for more details?
Check out the ELM Help Guide pages on SNMP Receiver.
|
Syslog Receiver 
The Syslog Receiver is configured to process Syslog messages from network devices and UNIX-based systems. Supporting both UDP and TCP, these messages are converted using the standard Windows event log format. Like Windows events, they are stored in the Primary database for reporting, Filtered to create concise Views and used to trigger a Notification. When used to supports firewalls, they fortify the security barrier around Windows networks.
Looking for more details?
Check out the ELM Help Guide pages on Syslog Receiver.
|
 |
|