Event Log View Online Getting Started Guide
Copyright 2002 Engagent
Sections:
A. The Event Log View Interface B. Run a Scan
C. Additional Features D. Support
A. The Event Log View Online Interface
from event log(s). The Content Pane contains the results of scans that are run with Event Log View.
2. Selected Machines Window -- this floating window is used to select a machine or group of machines to scan for events. Machine Lists can be created, saved, and deleted from this window.
3. Event Stat istics Window -- after a scan has been run and returned events, this floating window contains a count of the various types of events returned.
B. Run a Scan
Running a scan from start to finish consists of five basic steps. 1. Choose the machine(s) to scan
2. Choose an EventFilter to use
3. Specify any additional filtering/optimizing 4. Run the Query
5. Analyze the results
Choose the machine(s) to scan:
Using the Selected Machines window, you can create, select, or delete machine lists (of one or more machines). The Seleted Machines window is shown in detail below:
fig 1.2
To create a new list, click the “New List” button. This will open the “Select Machines” dialog, shown below:
fig 1.3
This dialog uses the computer’s Browser service to provide a list of machines
available on the network. To look for machines in another domain, simply select the ellipsis (“…”) button next to the Domain, and the program presents a secondary browser dialog.
Once a list has been created and has been selected, the machines on that list appear within the Selected Machines window, as below:
Service logs. The EventFilter list is shown in detail below, with an EventFilter selected:
fig 1.5
To begin a scan (also known as a query), click the Query button from the top of the Results Pane of the Main Window. The Selected Machines and/or Event Statistics windows may need to be moved or hidden in order to access the Query button; these windows can be toggled between show/hide using the toolbar buttons shown below:
fig 1.6
The Query button is the left-most button in the following image:
fig 1.7
The Query button is used to launch an entirely new query. The Requery button is used to relaunch a previously run query in order to further optimize or filter the scan. The Refresh button is used to refresh the data without mo difying the scan options. To start a new scan, click the Query button. Doing so will open the EventFilter dialog, as shown below:
fig. 1.8
Pre-defined filters will have some information already selected/included. To use the default settings for that filter, make no changes. To modify or futher filter, make changes to any of the items on the EventFilter dialog window (if nothing is selected, changed, or included on a filter except for the Event Types, the filter will return all
events for the specified event log).
Specify any additional filtering/optimizing:
Enhanced filtering options including creating lists of events, computers, or users.
- A comma separates lists items; (notice there is no space between list items) Workstation1,workstation2,workstation3
- Ranges on EventID utilize a dash; 624-644
When satisfied with the EventFilter settings, click OK to start the scan.
Run the query:
When the query (scan) is running, the window below indicates progress:
fig 1.9
The “Break” button can be used to stop a scan from completing if it is taking an inordinate amount of time to return (scans of millions of events, for instance). If the scan returned any events, it will then display them in the Results Pane of the Main Window. It is entirely possible for a scan to return no events if EventFilter parameters are too restrictive or if events do not exist within the Windows event logs. When events are returned, they will appear as below:
fig 1.10
Analyze the results:
Event Log View provides the Event Statistics window, as previously described, to indicate an overview of the events returned by the scan performed. A sample of the Event Statistics window is below:
The Results Pane columns can be rearranged in order to suit the user’s preference. To rearrange the columns, simply drag and drop them to the new location:
fig. 1.12
2. Print
Results returned by Event Log View scans can be printed in a simple report. Users have the ability to choose what data to include or exclude from a printed report. The print dialog is shown below:
fig 1.13
3. Export
In addition to printing, Event Log View can export results to a comma-delimited (.CSV) file for use by other programs. As with printing, data can be marked for inclusion or exclusion from export:
fig. 1.14
4. License
Once the product has been purchased, of if temporary evaluation keys have been issued, the key and activation string are entered on the License dialog window. This window can be accessed by selecting Help - > License from the menu:
fig. 1.15
Once the Activation String and Activation Key have been entered, clicking the “Transfer License Data” button will apply the license.
D. Support
Any questions or support issues can be directed to Engagent at the phone number and email address below. Additional information can also be found on the Engagent Web Site, also listed below:
Engagent
Toll-Free: (877) 820-7980 In WA State: (425) 485-8754
Email: [email protected]