Work with Event Sources panel
The Work with Event Sources panel allows you to define and work with Event Sources.
An Event Source is a location from which IBM i events are extracted. Currently, journals and message queues are supported as Event Sources. Common event sources are QAUDJRN (journal) and QSYSOPR (message queue). You may define your own journals and message queues as Event Sources.
How to Get There
On the Main Menu, choose option 1. Work with Event Sources.
Options
Opt
Enter a valid option from the list of options provided on the list panel.
Facility
The name you use to refer to this Event Source within Powertech SIEM Agent. It does not need to match the name of any object on the system; it is a name you invent for your reference.
This name is required to be a valid OS name.
Type
The type of object from which IBM i events will be extracted. Journals and message queues are supported as Event Sources. Common event sources are QAUDJRN (journal) and QSYSOPR (message queue).
Default Output
Indicates that there is, or is not, a set of Outputs attached to the Event Source that act as Default Outputs.
Names the default Output(s) to which syslog events will be sent for this Event Source. These Outputs will be used when a Rule specifies *SOURCE for a target Output.
Command Keys
F3=Exit
Exit the program.
F5=Refresh
Refreshes the panel with the most current data.
F6=Create
Creates a new item.
F12=Retrieve
Discards changes and returns to the prior panel.