EventLog Analyzer

事件日志和Syslog管理工具

面向:
EventLog Analyzer是一個綜合的事件日誌和Syslog管理工具。
  • 預置的SOX、HIPAA、PCI和GLBA順應性報表
  • 基於日誌的高級和通知
  • 在EventLog Analyzer服務器上歸檔日誌
  • 幫助提升企業的安全策略
 
成功案例
"EventLog Analyzer使收集日誌的工作變得簡單。我們每週都節約了大量時間"- Jin Ho, Cutera Inc. » 更多成功案例
 

EventLog Analyzer FAQ

General Product Information

  1. What is the difference between the Free Edition and the Professional Edition?
  2. Is a trial version of EventLog Analyzer available for evaluation?
  3. Does the trial version have any restrictions?
  4. Do I have to reinstall EventLog Analyzer when moving to the paid version?
  5. What hosts can EventLog Analyzer collect event logs from?
  6. I don't want to collect or report on actual event logs. Can I still use this product?
  7. How many users can access the application simultaneously?
  8. EventLog Analyzer runs in a web browser. Does that mean I can access it from anywhere?
  9. How do I buy EventLog Analyzer?
  10. Can EventLog Analyzer work if DCOM is disabled on remote systems?
  11. How to monitor Windows Events in EventLog Analyzer Linux Installation?
Installation
  1. What are the recommended minimum system requirements for EventLog Analyzer?
  2. Can I install EventLog Analyzer as a root user?
  3. When I try to access the web client, another web server comes up. How is this possible?
  4. Is a database backup necessary, or does EventLog Analyzer take care of this?
Configuration
  1. How do I add hosts to EventLog Analyzer so that it can start collecting event logs?
  2. How do I see session information of all users registered to log in to Firewall Analyzer?
  3. How long can I store data in the EventLog Analyzer database?
  4. How to move EventLog Analyzer to a different machine/server?
  5. How can I assign password to 'root' user in the EventLog Analyzer database?
Reporting
  1. Why am I seeing empty graphs?
  2. What are the types of report formats that I can generate?
Can't find an answer here? Check out the EventLog Analyzer user forum

What is the difference between the Free and Professional Editions?

The Free Edition of EventLog Analyzer is limited to handling event logs from a maximum of five hosts, whereas the Professional Edition can handle event logs from an unlimited number of hosts. There is no other difference between the two editions, with respect to features or functionality.

Is a trial version of EventLog Analyzer available for evaluation?

Yes, a 30-day free trial version can be downloaded here. At the end of 30 days it automatically becomes a Free Edition, unless a new license is applied.

Does the trial version have any restrictions?

The trial version is a fully functional version of EventLog Analyzer Premium Edition. When the trial period expires, EventLog Analyzer automatically reverts to the Free Edition.

Do I have to reinstall EventLog Analyzer when moving to the paid version?

No, you do not have to reinstall or shut down the server. You just need to enter the new license file in the Upgrade License box.

Back to Top

What hosts can EventLog Analyzer collect event logs from?

This depends on the platform on which EventLog Analyzer is installed. If installed on a Windows machine, EventLog Analyzer can collect event logs or syslogs from Windows and Unix hosts, Cisco Switches and Routers, and other syslog devices . If installed on a Unix machine, EventLog Analyzer can collect syslogs only from Unix hosts, Cisco Switches and Routers, and other syslog devices.

I don't want to collect and report on actual event logs. Can I still use this product?

You can still use EventLog Analyzer to simulate event logs and see how reports will look like when real-time data is used. Click the Simulate link in the Settings tab to begin sending sample event logs to EventLog Analyzer.

How many users can access the application simultaneously?

This depends only on the capacity of the server on which EventLog Analyzer is installed. The EventLog Analyzer license does not limit the number of users accessing the application at any time.

Back to Top

EventLog Analyzer runs in a web browser. Does that mean I can access it from anywhere?

Yes. As long as the web browser can access the server on which EventLog Analyzer is running, you can work with EventLog Analyzer from any location.

How do I buy EventLog Analyzer?

You can buy EventLog Analyzer directly from the Manageengine Online Store, or from a reseller near your location.

Can EventLog Analyzer work if DCOM is disabled on remote systems?

No. EventLog Analyzer cannot work if DCOM is disabled on remote systems. You need to have DCOM enabled in remote windows servers for the logs to get collected and shown in EventLog Analyzer.

How to monitor Windows Events in EventLog Analyzer Linux Installation?

To monitor Windows Events in ELA Linux Installation, you need to convert Windows Event messages into Syslog messages. To convert the message you have to use separate tool.

Back to Top

What are the recommended minimum system requirements for EventLog Analyzer?

It is recommended that you install EventLog Analyzer on a machine with the following configuration:
* Processor - Pentium 4 - 1.5GHz
* Disk Space - 1GB * RAM - 512MB
* Operating System - Windows 2000/XP/2003, Linux 8.0/9.0
* Web Browser - Internet Explorer 6.0, or Mozilla Firefox 1.0

Look up System Requirements to see the minimum configuration required to install and run EventLog Analyzer.

Can I install EventLog Analyzer as a root user?

EventLog Analyzer can be started as a root user, but all file permissions will be changed, and later you cannot start the server as another user.

When I try to access the web client, another web server comes up. How is this possible?

The web server port you have selected during installation is possibly being used by another application. Configure that application to use another port, or change the EventLog Analyzer web server port.

Back to Top

Is a database backup necessary, or does EventLog Analyzer take care of this?

The archiving feature in EventLog Analyzer automatically stores all logs received in zipped flat files. You can configure archiving settings to suit the needs of your enterprise. Apart from that, if you need to backup the database, which contains processed data from event logs, you can run the database backup utility, BackupDB.bat/.sh present in the <EventLogAnalyzer_Home>/troubleshooting directory.

How do I add hosts to EventLog Analyzer so that it can start collecting event logs?

For Windows hosts, enter the host name and the authentication details, and then add the host. For Unix hosts, enter the host name and the port number of the syslog service, and then add the host. (Ensure that the syslog service is running, and that it is using the same port number specified here.)

How do I see session information of all users registered to log in to EventLog Analyzer?

The session information for each user can be accessed from the User Management link. Click the View link under Login Details against each user to view the active session information and session history for that user.

How to move EventLog Analyzer to a different machine/server?

Please follow the below steps to move an existing EventLog Analyzer server to a new machine/server.

MySQL database

  1. Stop the existing EventLog Analyzer server/service
  2. Ensure that the process 'java.exe', 'mysqld-nt.exe' and 'SysEvtCol.exe' are not running/present in the task manager, kill these process manually if any them are still running
  3. As a precautionary measure, copy the following complete folders (including the files and sub-folders) to another drive or to a mapped network drive. This will help us to restore to the settings and data in-case of any issue with the new machine installation.
    • The folder, MySQL located under EventLog Analyzer Home\
    • The folder, Archive located under EventLog Analyzer Home\archive
  4. Please download and install in the new machine/server the latest build of Eventlog Analyzer from the following link: http://www.manageengine.com/products/eventlog/download.html
  5. Do not start the newly installed EventLog Analyzer server/service.
  6. In the newly installed EventLog Analyzer machine/server, rename the folder MySQL located under EventLog Analyzer Home\ as OldMySQL.
  7. Copy the MySQL folder (including the files and sub-folders), which is located under EventLog Analyzer Home\ , from the old machine/server to the newly installed Eventlog Analyzer machine/server.
    Note: Kindly take extra care that the EventLog Analyzer is not running on both the systems while performing this operation.
  8. Start the EventLog Analyzer on the new machine and check whether the data and configurations are intact.

MSSQL database

  1. Stop Eventlog Analyzer server/service.
  2. Download and install the latest build of Eventlog Analyzer from the following link:
    http://www.manageengine.com/products/eventlog/download.html
  3. Once you install the application in the new machine, kindly make sure that you do not start the application or shutdown the Eventlog Analyzer if started.
  4. Please configure the MSSQL server credentials of the earlier Eventlog Analyzer server installation as explained in the Configuring MSSQL Database topic.
  5. Start the Eventlog Analyzer server/service on the new machine and check whether the data and the configurations are intact.

In-case of any issues while performing the above steps, please do not continue any further and contact support@eventloganalyzer.com to assist you better.

Back to Top

How long can I store data in the EventLog Analyzer database?

The DB Storage Options box in the Settings tab lets you configure the number of days after which the database will be purged. The default value is set at 32 days. This means that after 32 days, only the top values in each report are stored in the database, and the rest are discarded.

How can I assign password to 'root' user in the EventLog Analyzer database?

To assign/change MySQL Database password, follow the below given steps:
  • Connect to EventLog Analyzer's MySQL. Go to <EventLog Analyzer Home>/mysql directory, execute the following command 
./bin/mysql -u root- h localhost-- port=33335 -D EVENTLOG
  • Execute the following queries in the database

USE mysql

update user set password=password ('New Password') where user = 'root';

FLUSH PRIVILEGES;

  • Stop EventLog Analyzer.
  • Go to <EventLog Analyzer Home>/data directory, edit dbparam.conf
  • File and change the password to the 'New' password.
  • Restart EventLog Analyzer.
Why am I seeing empty graphs?

Graphs are empty if no data is available. If you have started the server for the first time, wait for at least one minute for graphs to be populated.

What are the types of report formats that I can generate?

Reports can be generated in HTML, CSV, and PDF formats. All reports are generally viewed as HTML in the web browser, and then exported to CSV or PDF format. However, reports that are scheduled to run automatically, or be emailed automatically, are generated only as PDF files.

Back to Top
 
EventLog Analyzer Download