2018-01-04 11:03 AM
Hi Team,
How can we ensure that logs are coming all servers to log collector ,is there any way to find the status .Kindly suggest.
2018-01-04 11:36 AM
that is what Event Sources > Monitoring policies is to be used for. THere is automatic monitoring settings where devices are baselined day over day and week over week to detect deviations of more than the std deviation defined in the config.
a server could be busy during the week day and then send no logs during weekend... a static policy of more or less than x events per period would alert constantly on the weekend... that was what the auto monitor policy was designed for.
have you looked into those functions?
2018-01-04 11:48 AM
No Eric ,it is possible to generate any health report or SA creates any alerts
2018-01-04 12:19 PM
policy will create alerts for devices that you assign high and low watermarks. those can be send via your standard notification templates for email, syslog etc.
you can also use ESA with the template alert to notify when a device(s) have not sent events for a period of time and that also has alerting options or ability to roll up into IM/Respond interface.