Use this procedure to enable an r8 SP2 CA Audit client to send events to both CA User Activity Reporting Module and the CA Audit collector database. By adding a new target to the Route or Collector actions on an existing rule, you can send collected events to both systems. As an alternative, you can also modify specific policies or rules to send events only to the CA User Activity Reporting Module server.
More information on working with policies is available in the CA Audit r8 SP2 Implementation Guide. Refer to that resource for details on performing the steps in the procedure that follows.
CA User Activity Reporting Module collects events from CA Audit clients using the CA Audit SAPI Router and CA Audit SAPI Collector listeners. Collected events are stored in the CA User Activity Reporting Module event log store only after you push the policy to the clients and it becomes active.
Important: You must configure the CA User Activity Reporting Module listeners to receive events before you modify and activate the policy. If you do not do this configuration first, you may have incorrectly mapped events between the time that the policy becomes active and the listeners can correctly map the events.
To modify an existing r8 SP2 policy rule's action to send events to CA User Activity Reporting Module
The policy appears in the Details pane, displaying its rules.
The rule appears, with its actions displayed, in the Details pane.
The Edit Rule wizard appears.
After the policy is approved, the Policy Manager Distribution Server's settings determine when the new policy is distributed to the audit nodes. You can review the activation log to check on a policy's activation status.
Copyright © 2013 CA.
All rights reserved.
|
|