Previous Topic: Create a Connector Based on NTEventLog

Next Topic: View Logs from Windows Event Sources

Configure a Windows Event Source

After configuring a connector using the NTEventLog integration on the agent, you should be able to see events through your Event Viewer. If events are not being forwarded to your event viewer, you should change the Windows settings for your Local Policies on the event source.

To configure local policies on the event source for a NTEventLog connector

  1. If the Log Collection Explorer is not already displayed, click the Administration tab.
  2. Expand Event Refinement Library, expand Integrations, expand Subscription, select NTEventLog, and click the Help link above the Integration Name on the View Integration Details pane.

    The Connector Guide for NT Event Log (Security, Application, System) appears.

  3. Minimize the CA Enterprise Log Manager user interface and follow the directions in the Connector Guide for editing local policies on an event source running on a Windows operating system.

    Note: If your system is Windows Server 2003, select Control Panel, Administrative Tools, Local Security Policy, and then expand Local Policies.

  4. (Optional) If you configured a WMI Sensor for a second WMI server, edit the local policies on that server also.
  5. Maximize CA Enterprise Log Manager.