Previous Topic: Custom Report Creation

Next Topic: API Access

Agent Management

Connector Configuration on an Agent

A connector is a collection process that runs under the control of an agent and collects and processes events from a single log source. A connector, which connects with a specific device, uses an integration that provides the rules for connecting with that specific type of device.

Procedure

More Information

Agent Management Tasks

Configure the Syslog Connector for the Default Agent

Configure a Windows Connector for the Agent

View Logs from Windows Event Sources

Event Filtering with Suppression Rules

Suppression rules are rules you configure to prevent certain raw events from appearing in your reports. You can create permanent suppression rules to suppress routine events of no security concern and you can create temporary rules to suppress the logging of planned events such as the creation of many new users.

Procedure

More Information

Creating a Suppression Rule

How to Apply Suppression and Summarization on Agent Components

Suppression Rule Effects

Event Summarization with Summarization Rules

Summarization rules are rules that combine certain native events of a common type into one refined event. For example, a summarization rule can be configured to replace up to 1000 duplicate events that have the same source and destination IP addresses and ports with a single summarization event. Such rules simplify event analysis and reduce log traffic.

Procedure

More Information

Creating a Summarization Rule

 

Group-based Node Organization

An agent group allows agents to be associated together for management purposes. Agents can belong to only one group. Agents that are not assigned to a group belong to the Default Group.

Procedure

More Information

Creating an Agent Group

Configuring Agent Management

About Agent Groups


Copyright © 2010 CA. All rights reserved. Email CA about this topic