Previous Topic: Use the Host Prompt

Next Topic: Use the Log Name Prompt

Use the IP Prompt

The IP prompt queries for events where the IP address you specify appears in the selected CEG fields of the refined event. When raw event data is refined, event details can include several different CEG IP addresses. Consider this scenario:

  1. The event initiator on source_address attempts an act, event_action, on a target residing on dest_address.

    Note: Source_address and dest_address can be different or the same.

  2. This event is recorded in a repository on event_source_address.

    Note: Event_source_address can be different from either source_address or dest_address or can be the same as one or both.

  3. A CA Enterprise Log Manager agent installed on agent_address makes a copy of the event recorded on event_source_address

    Note: Agent_address is the same as event_source_address in agent-based log collection but is different in agentless and direct log collection.

  4. The agent on agent_address transmits the copy of the event in event_logname to a CA Enterprise Log Manager collection server.

To use the IP prompt

  1. Select Queries and Reports.

    The Query List displays the Prompts folder and one or more folders for other queries.

  2. Expand Prompts and select Host.

    The IP prompt appears.

  3. Enter the IP address on which to base this query.
  4. Select one or more of the following fields to query for data matching your IP address entry.
  5. Click Go.

    Results of the IP prompt query appear.

  6. Use the following descriptions to interpret the query results:


Copyright © 2010 CA. All rights reserved. Email CA about this topic