2016-03-07 03:13 PM
I think I understand the idea of an identity feed - authentication log data associating user identity to IP addresses (and possibly computer names?) is turned into a feed, so that future activity from the IP address is automatically tagged with the ID. But I haven't been able to find any useful explanation of the specifics, nor to get one working.
I've apparently made an identity feed on a log collector service with default parameters (because I don't know what the parameters are, so I wouldn't know what values to enter for them).
Now, where to find this feed file to check if it has any content? The host with the log collector service doesn't have any listeners on port 80 or 443, there doesn't seem to be an obvious web service to check.
The documentation of this is a bit... sparse. The 10.5 help doc gets you as far as "be in the Event Destinations tab of the log decoder config view" and then leaves you to fend for yourself.
https://sadocs.emc.com/0_en-us/089_105InfCtr/135_LCGds/20_LCCG/20_LCCGRef/15EvtDestTab
The 10.2 documentation gets all the way to "This is the screen you'll be scratching your head at. Enter the correct information. Good luck guessing what any of it means"
I wish I could ask a more specific question, but I'm sufficiently baffled I don't know where to start
Thanks very much
2016-03-08 11:15 AM
I helped write a document about this a while back. I think you are probably at the point where you could skip to page 17 of the doc for the Identity setup.
Let me know if it helps.
Chris
2016-03-08 11:15 AM
2016-03-08 12:06 PM
Brilliant, thank you Chris! That's very helpful!