When you deploy Log Collection, you must configure the Log Collectors to collect the log events from various event sources, and to deliver these events reliably and securely to the Log Decoder host, where the events are parsed and stored for subsequent analysis.
This topic introduces features of the Services Config view > Remote Collectors/Local Collectors tab.
Workflow
This workflow illustrates the basic tasks needed to start collecting events through Log Collection.
What do you want to do?
Role | I Want to... | Documentation |
---|---|---|
Administrator | Perform basic Log Collection implementation | Log Collection: Basic Procedure for All ProtocolsBasic Implementation |
Administrator | Set up a lockbox to maintain lockbox settings. | Set Up a Lockbox |
Administrator | Start Log Collection services. | Log Collection: Start Collection Services and Enable Automatic StartStart Collection Services |
Administrator | *Configure Log Collection protocols and event sources. | Configure Collection Protocols and Event Sources |
Administrator | Verify that Log Collection is working. |
*You can perform this task here.
Related Topics
Services Config View
The Services Config view is the view on which you maintain all the Log Collection parameters. The tab in which you maintain the deployment parameters referred to in this guide is the Remote/Local Collectors tab:
- If you are configuring a Local Collector , NetWitness Platform displays the Remote Collectors tab so that you can configure the Local Collector to pull events from Remote Collectors.
- If you are configuring a Remote Collector , NetWitness Platform displays the Local Collectors tab so that you can configure the Remote Collector to push events to a Local Collector .
Remote Collectors Tab
On a Local Collector, the Remote Collectors panel provides a way to add or delete Remote Collectors from which the Local Collector pulls events.
Local Collector Tab
On a Remote Collector , the Local Collector panel provides a way to add or delete the Local Collectors to which you want to the Remote Collector to push events.
Select the Destination or Source in the Select Configuration drop-down menu.
- Destination displays the Add Remote Destination dialog.
- Source displays the Add Source dialog.
The following table describes the Add Source dialog.
The following table describes the Local Collectors Panel.