The port prompt queries for events where the port you specify appears in the selected CEG fields of the refined event. When raw event data is refined, event details can include several different CEG port numbers. Consider this scenario:
Note: Source_port and dest_port are the same for local events. Otherwise, they are host-specific.
Note: The agent uses port 17001, by default, to secure communications to the CA Enterprise Log Manager collection server.
To use the Port prompt
The Query List displays the Prompts folder and one or more folders for other queries.
The Port prompt appears.
Is the communications port used for initiating the action.
Is the communication port on the destination host that is the target of the action.
Is the port that the agent uses to communicate with the CA Enterprise Log Manager collection server.
Results of the port prompt query appear.
Indicates the severity of the event, where the values in increasing order of severity include: Information, Warning, Minor Impact, Major Impact, Critical, and Fatal.
Indicates when the event occurred.
Identifies the IP address of the host from which the event action was initiated.
Specifies a code for the event result of the corresponding action, where S means Success, F means Failure, A means Accepted, D means Dropped, R means Rejected, and U means Unknown.
Identifies the outbound port used for initiating the action.
Identifies the inbound port on the destination host.
Identifies the outbound port on the agent used to send event logs to the CA Enterprise Log Manager server.
Identifies the high-level category of the corresponding event action. For example, System Access is the category for the Authentication action.
Identifies the event action.
Identifies the log name used by the connector that collected the event.
Copyright © 2011 CA. All rights reserved. | Email CA Technologies about this topic |