• No results found

TECHNICAL NOTE INSTALLING AND CONFIGURING ALE USING A CLI. Installing the Adaptive Log Exporter

N/A
N/A
Protected

Academic year: 2021

Share "TECHNICAL NOTE INSTALLING AND CONFIGURING ALE USING A CLI. Installing the Adaptive Log Exporter"

Copied!
8
0
0

Loading.... (view fulltext now)

Full text

(1)

I

NSTALLING

AND

C

ONFIGURING

ALE U

SING

A

CLI

NOVEMBER 2010

If you want to install the Adaptive Log Exporter without the installation wizard, this document provides information about installing the Adaptive Log Exporter using a command line interface (CLI) utility. This CLI utility allows you to deploy your Adaptive Log Exporter to multiple remote systems in your deployment using any third-party product that allows remote or batch installs, for example, MSI

Packaging Tools or Message-Oriented Middleware (MOM).

Note: The procedures in this document assume an advanced knowledge of network administration.

This document includes:

Installing the Adaptive Log ExporterUpdating Your Windows Event Log DeviceUpdating Your TCP Syslog Plug-in

Adaptive Log Exporter CLI Utility ExamplesWindows Event Log Device CLI Utility ExamplesTCP Syslog Plug-in CLI Utility Examples

Installing the

Adaptive Log

Exporter

To install the Adaptive Log Exporter using a CLI:

Step 1 Obtain the Adaptive Log Exporter CLI utility from the Juniper customer support web site:

www.juniper.net/support/

Note: Once you download the Adaptive Log Exporter CLI utility, you must select a distribution method to deploy the Adaptive Log Exporter to remote systems in your deployment.

Step 2 Close all other active applications before installing the Adaptive Log Exporter.

Step 3 In a Windows CLI, enter the following command:

(2)

2 TECHNICAL NOTE

Note: The SP-, VERYSILENT, and SUPPRESSMSGBOXES parameters are required parameters for each command entry.

Step 4 Enter parameters, as necessary. For more information, see Parameters.

Parameters When entering the CLI utility options, the following parameters are available: • Required Parameters

Optional Parameters

Windows Event Log Monitoring Parameters

Note: All parameters are case sensitive.

Required Parameters

The following parameters are required for the CLI utility: /SP- /VERYSILENT /SUPPRESSMSGBOXES

Optional Parameters

The following table provides the optional parameters for use with the CLI utility: Table<n=1> Optional Parameters

Parameter Description

/DIR Specify the fully qualified path name to the destination directory for the Adaptive Log Exporter installation files. By default, the Adaptive Log Exporter is installed in the Program

Files/Adaptive Log Exporter directory.

/COMPONENTS Specify the list of Adaptive Log Exporter components you want to install. The options are:

main - Mandatory. You must specify this parameter to install the base components of the Adaptive Log Exporter service.

ui - Specify this parameter to install the user interface. If you do not specify any parameters in the /COMPONENTS option, the main and ui components are installed by default. /NOICONS Specify if you do not want to include the Adaptive Log Exporter

icon to appear in your Start menu options.

(3)

Windows Event Log Monitoring Parameters

The Windows event log monitoring parameters allow you to automatically create a Windows event log device and a corresponding syslog destination. All of the below parameters must be included in the command.

The following table provides the Windows event log monitoring parameters:

Updating Your

Windows Event

Log Device

Once you have installed the Adaptive Log Exporter using the CLI utility (see Installing the Adaptive Log Exporter), you can use the CLI utility to update your Windows Event Log Device configuration.

Your Windows Event Log Device must be configured in your deployment before you update your Windows Event Log Device using the CLI. Also, ensure your Windows Event Log Device configuration includes the default configuration values before you apply the update.

To update your Windows Event Log Device configuration:

Step 1 Download the Windows Event Log Device plug-in from the Juniper customer support web site:

www.juniper.net/support/

Step 2 Close all other active applications before installing the Windows Event Log Device plug-in.

Step 3 In a Windows CLI, enter the following command:

ALE_WindowsEventLogPlugin_setup.exe /SP- /VERYSILENT /SUPPRESSMSGBOXES /PATCHONLY

Note: The SP-, VERYSILENT, and SUPPRESSMSGBOXES parameters are required parameters for each command entry.

Table 1-1 Windows Event Log Monitoring Parameters Parameter Description

/MONITOR Specify using a comma separated list of event logs you want to monitor. For example:

/MONITOR=Application,Security,System

/MONITORDEST Specify the syslog destination that you want to receive the logs. You can specify this value in an <IP address or hostname>:<port> format. The port number defaults to 514 if not specified.

/MONITORPROTO Specify the protocol to use when sending syslog log files. The protocol can be specified as TCP or UDP. The protocol defaults to UDP if not specified.

(4)

4 TECHNICAL NOTE

Step 4 Enter parameters, as necessary.

Updating Your TCP

Syslog Plug-in

Once you have installed the Adaptive Log Exporter using the CLI utility (see Installing the Adaptive Log Exporter), you can use the CLI utility to update your TCP Syslog plug-in.

To update the TCP Syslog plug-in using the CLI:

Step 1 Download the TCP Syslog plug-in from the Juniper customer support web site: www.juniper.net/support/

Step 2 Close all other active applications before installing an update to the TCP Syslog plug-in.

Step 3 In a Windows CLI, update the plug-in using the following command: ALE_WindowsEventLogPlugin_setup.exe /SP- /VERYSILENT /SUPPRESSMSGBOXES /PATCHONLY

Note: The SP-, VERYSILENT, and SUPPRESSMSGBOXES parameters are required parameters for each command entry.

Step 4 Enter parameters, as necessary.

Table 1-2 Windows Event Log Monitoring Parameters Parameter Description

/MONITOR Specify using a comma separated list of event logs you want to monitor. For example:

/MONITOR=Application,Security,System

/MONITORDEST Specify the syslog destination that you want to receive the logs. You can specify this value in an <IP address or hostname>:<port> format. The port number defaults to 514 if not specified.

/DEVICEADDRESS Specify the hostname or IP address you want to use in the syslog header when events are created. To the syslog

receiver, this appears as though this device address generated the message.

/PATCHONLY Specify this parameter if you update your configuration to a later version of the Windows Event Log plug-in without modifying the existing configuration.

Table 1-3 Windows Event Log Monitoring Parameters Parameter Description

/MONITOR Specify using a comma separated list of event logs you want to monitor. For example:

/MONITOR=Application,Security,System

(5)

Adaptive Log

Exporter CLI Utility

Examples

This section provides several examples of using the CLI utility including: • Install Service Only

Service Only Monitoring Windows Security LogFull Install

Full Install Monitoring Windows Security Logs

Install Service Only If you want to install the Adaptive Log Exporter functionality without the user interface, enter the following command:

AdaptiveLogExporter_setup /SP- /VERYSILENT /SUPPRESSMSGBOXES /COMPONENTS=main

Service Only Monitoring Windows Security Log

If you want to install the Adaptive Log Exporter functionality without the user interface, and you also want to monitor Windows security logs and send events using the default syslog port (UDP port 514), enter the following command: AdaptiveLogExporter_setup /SP- /VERYSILENT /SUPPRESSMSGBOXES /COMPONENTS=main /MONITOR=Security /MONITORDEST=10.10.100.100 /DEVICEADDRESS=Device hostname or IP address

Full Install If you want to the fully install the Adaptive Log Exporter, including the user interface and requiring no further configuration, enter the following command: AdaptiveLogExporter_setup /SP- /VERYSILENT /SUPPRESSMSGBOXES /COMPONENTS=main,ui

Full Install Monitoring Windows Security Logs

If you want to fully install the Adaptive Log Exporter, including the user interface and the ability to monitor Windows Security Logs, enter the following command: AdaptiveLogExporter_setup /SP- /VERYSILENT /SUPPRESSMSGBOXES /COMPONENTS=main,ui /MONITOR=Security /MONITORDEST=Syslog Destination hostname or IP address /DEVICEADDRESS=Device hostname or IP address

/DEVICEADDRESS Specify the hostname or IP address you want to use in the syslog header when events are created. To the syslog

receiver, this appears as though this device address generated the message.

/PATCHONLY Specify this parameter if you update your configuration to a later version of the Windows Event Log plug-in without modifying the existing configuration.

(6)

6 TECHNICAL NOTE

Windows Event

Log Device CLI

Utility Examples

This section provides several examples of using the CLI utility to update your Windows Event Log Device including:

Update IP Address for Windows Event Log DeviceUpdate Logs Monitored for Windows Event Log DeviceCopy Files for Windows Event Log ConfigurationAdd a New Windows Event Log Device

Update IP Address for Windows Event Log Device

If you install the Windows Event Log Device plug-in and want to modify the IP address of the Window Event Log Device, enter the following command: ALE_WindowsEventLogPlugin_setup.exe /SP- /VERYSILENT

/SUPPRESSMSGBOXES /DEVICEADDRESS=Device hostname or IP address

Update Logs Monitored for Windows Event Log Device

If you install the Windows Event Log Device plug-in and want to change the type of logs you are monitoring, enter the following command:

ALE_WindowsEventLogPlugin_setup.exe /SP- /VERYSILENT /SUPPRESSMSGBOXES /MONITOR=Security,System

Copy Files for Windows Event Log Configuration

If you install the Windows Event Log Device plug-in and want to preserve your existing configuration while copying the necessary updated files from a patch, enter the following command:

ALE_WindowsEventLogPlugin_setup.exe /SP- /VERYSILENT /SUPPRESSMSGBOXES /PATCHONLY

Add a New Windows Event Log Device

To install a new Windows Event Log Device plug-in, enter the following command: ALE_WindowsEventLogPlugin_setup.exe /SP- /VERYSILENT

/SUPPRESSMSGBOXES /COMPONENTS=main /DEVICEADDRESS=Device hostname or IP address /MONITOR=Security,Application,System /MONITORDEST=Syslog Destination hostname or IP address:514

TCP Syslog Plug-in

CLI Utility

Examples

This section provides several examples of using the CLI utility to update your TCP Syslog plug-in including:

Update IP Address for TCP Syslog Plug-inUpdate Logs Monitored for a TCP Syslog Plug-inCopy Files for TCP Syslog Plug-in

Add a New TCP Syslog Plug-in

Update IP Address for TCP Syslog Plug-in

If you install the TCP Syslog plug-in and want to modify the device address, enter the following command:

ALE_TCPSyslogPlugin_setup.exe /SP- /VERYSILENT

(7)

Update Logs Monitored for a TCP Syslog Plug-in

If you install the TCP Syslog plug-in and want to change the type of logs you are monitoring, enter the following command:

ALE_TCPSyslogPlugin_setup.exe /SP- /VERYSILENT /SUPPRESSMSGBOXES /MONITOR=Security,System

Copy Files for TCP Syslog Plug-in

If you install the TCP Syslog plug-in and want to preserve your existing

configuration while copying the necessary updated files from a patch, enter the following command:

ALE_TCPSyslogPlugin_setup.exe /SP- /VERYSILENT /SUPPRESSMSGBOXES /PATCHONLY

Add a New TCP Syslog Plug-in

To install the TCP Syslog plug-in on a new device, enter the following command: ALE_TCPSyslogPlugin_setup.exe /SP- /VERYSILENT

(8)

Juniper Networks, Inc.

1194 North Mathilda Avenue Sunnyvale, CA 94089 USA

408-745-2000 www.juniper.net

Copyright Notice

References

Related documents

There may be other reasons that the DCA is not collecting complete information, for example, the device does not store a specific data field (toner levels, etc.), or a Local Print

The Context level is useful, for example, if you want to execute several commands directed at the same port or VLAN, or if you want to shorten the command strings for a

 Exporter must have entered into export contract with foreign buyer  Exporter must have financial &amp; technical means. 70% SA content required on all export

Problems with the first road ­ Drop­out of the system: in the EU about  15% = 6 million young people between  18­24 years old have left this road  prematurely

© ROIC Pty Ltd T/A Horse Racing Software 2007  20 of 20  Scanning Mode  The last step is to turning scanning mode ON. 

Enough evoo to family farm to turkey burgers cooking instructions on the package you can make money from an affiliate links to make juicy turkey burgers were tasty. Hiding in

For the purposes of this Note, and in fact for most issues of statu- tory interpretation in this area, the federal mail fraud 19 and wire fraud statutes 20 are

Connect4Growth provides its clients and vendors with professional and responsive ”connection” advisory services as well as being the market-leading provider of vendor