The IP prompt queries for events where the IP address you specify appears in the selected CEG fields of the refined event. When raw event data is refined, event details can include several different CEG IP addresses. Consider this scenario:
Note: Source_address and dest_address can be different or the same.
Note: Event_source_address can be different from either source_address or dest_address or can be the same as one or both.
Note: Agent_address is the same as event_source_address in agent-based log collection but is different in agentless and direct log collection.
To use the IP prompt
The Query List displays the Prompts folder and one or more folders for other queries.
The IP prompt appears.
Is the IP address of the host where the action was initiated.
Is the IP address of a host that is the destination or target of the action.
Is the IP address of a host that records the raw event when the event occurs.
For example, you can deploy a connector based on WinRM to collect events from the Event Viewer on a Windows Server 2008 host. To select events retrieved from a given Windows Server 2008 host, enter the IP address of that server and select this field.
Is the same as agent_address.
Is the IP address of a host where a CA Enterprise Log Manager agent is deployed.
Results of the IP prompt query appear.
Indicates the severity of the event, where the values in increasing order of severity include: Information, Warning, Minor Impact, Major Impact, Critical, and Fatal.
Indicates when the event occurred.
Provides a code for the result of the corresponding action, where the displayed letter has the following meaning: S for success, F for failure, A for Accepted, D for Dropped, R for Rejected, and U for Unknown.
Identifies the communication port on the destination host, the target of the event action.
Identifies the IP address from which the event action was initiated.
Identifies the IP address of the host that was the target of the event action.
Identifies the IP address of the host with the repository where the event was originally recorded.
Identifies the name of the host with the CA Enterprise Log Manager agent responsible for the collection of events from the event source.
The same as Agent IP.
Identifies the high-level category of the corresponding event action. For example, System Access is the category for the Authentication action.
Identifies the event action.
Identifies the log name used by the connector that collected the event
Copyright © 2011 CA. All rights reserved. | Email CA Technologies about this topic |