Getting Started and Understanding Logs

Logs Agent Installation

For Windows Servers:

To run Logs, you need to install Logs agents in every Windows server containing the log files you want to monitor. Logs agent will monitor and filter the log files then report your specific log messages back to Chroniker.

Chroniker Suite comes with a local Logs Agent which can monitor Windows events and log files in the server where Chroniker is installed.

If you need more Windows agents, please refer to the following link to download the Logs agent that is appropriate to your platform: http://www.nrgglobal.com/downloads/logwatch_agent_downloads.php

Follow the installer program. Specify the installation path and agent listener port when prompted.

For All other servers and network devices:

Logs will receive Syslog messages from all your other servers and syslog enabled devices. Therefore, you need to enable Syslog in the devices containing the log files you want to monitor. For detailed instructions on how to setup Syslog configuration, please refer to " Configuring Syslog Enabled Devices " section below.

Logs Configuration

After Logs Agents are installed, you need to set up the log files to be monitored in the Chroniker Logs monitor by:

  1. Defining the Logs agent to enable Chroniker base to connect to the agent
  2. Organizing your logs from all the agents into Facilities. A Facility is a set of one or more log files that share the following characteristics: agent, scan frequency, filters, and events. You can define multiple Facilities per agent. An example of how a Facility may be used is to group all the log files of a certain application.

1. Define the Logs Agent:

2. Add a Facility:

A Facility is a logical grouping of multiple log files on one agent.  A Facility can have more than one log file, and an agent can have more than one Facility.  The purpose of a Facility is for simplicity in monitoring: so you can view all log messages in one place, apply the same filters and reactions to all the logs in the Facility, etc.  An example of how a Facility may be used is to group all the log files of a certain application.