Automatic tab

Use the Automatic tab to schedule log file data collections. Log file data consists of journal entries written to the system audit journal, QAUDJRN. You can define Automatic data collections at both the Consolidator and Endpoint levels.

Automatic Assessments allow you to define criteria for the amount of data you want to collect from the Endpoint systems.

How to Get There

Right-click the Consolidator and choose Properties, then choose the Automatic tab.

 

You can specify the following for an automatic assessment:

  • Frequency to harvest data: Specify how often to collect log file data. You can set collection frequency by number of hours or days. You can specify any number between 1 and 999.
  • Start day and time: Select the day of the week (Sunday through Saturday) and the time to begin the log file data collections. Time options are in half-hour increments.

Use the Available types and Selected types fields to select the journal entry types you want to harvest:

  • Available types: Lists the journal entry types that are available for data collections. The Available types field displays the following information:
    • Code
    • Type
    • Description
    • Journal
  • Selected types: Lists the journal entry types selected for the log file data collections.

You can add or remove journal entry types from either the Available types or Selected types fields. Click an entry type, and then click the applicable arrow to move the entry to the appropriate field. Click the double arrows to move all entry types. When you finish making your selections, click OK to save your changes.

At the Endpoint Level

When you define automatic assessments at the Endpoint level, you can choose either to use the Consolidator defaults or define different criteria for the data collection.

  • Use Consolidator defaults: Select this check box if you want the Endpoint log file data collections to be set the same as the Consolidator. This disables all other options, except Prevent deletion.

If you don't want to use the Consolidator defaults, you can specify the collection criteria for the Endpoint.

  • Prevent deletion: Select this to prevent deletion of the automatic log file data collection.
    NOTE: This option is available only at the Endpoint level.