The host prompt queries for events where the hostname you specify appears in the selected CEG fields of the refined event. When raw event data is refined, event details can include several different CEG host names. Consider this scenario:
Note: Source_hostname and dest_hostname can be different hosts or the same host.
Note: Event_source_name can be a different host than either source_hostname or dest_hostname or can be colocated.
Note: Agent_hostname is the same as event_source_name in agent-based log collection but is different in agentless and direct log collection.
To use the Host prompt
The Query List displays the Prompts folder and one or more folders for other queries.
The Host prompt appears.
Is the name of the host where the event action was initiated.
Is the name of a host that is the destination or target of the action.
Is the name of a host that records the event when the event occurs.
For example, you can deploy a connector based on WinRM to collect events from the Event Viewer on a Windows Server 2008 host. To select events retrieved from a given Windows Server 2008 host, enter the hostname of that server and select this field.
Is the same as agent_hostname.
Is the name of the host where a CA Enterprise Log Manager agent is deployed.
Results of the host prompt query appear.
Indicates the severity of the event, where the values in increasing order of severity include: Information, Warning, Minor Impact, Major Impact, Critical, and Fatal.
Indicates when the event occurred.
Identifies the name of the user on source_hostname who initiated the event action.
Specifies a code for the event result of the corresponding action, where S means Success, F means Failure, A means Accepted, D means Dropped, R means Rejected, and U means Unknown.
Identifies the name of the host where the CA Enterprise Log Manager agent who collected the event is installed.
The same as agent host.
Identifies the high-level category of the corresponding event action. For example, System Access is the category for the Authentication action.
Identifies the event action performed by the source user.
Identifies the log name used by the connector that collected the event. All connectors based on the same integration transmit events in a log file with the same log name.
Copyright © 2011 CA. All rights reserved. | Email CA Technologies about this topic |