- Related Products
- ADManager Plus
- ADAudit Plus
- ADSelfService Plus
- Exchange Reporter Plus
- AD360
- Log360
EventLog Analyzer processes log data across your network and provides reports on session activity of your network devices and users. You can access these reports by clicking on Activity Monitoring under the Correlation tab.
You can either use the predefined rules in EventLog analyzer to generate reports on session activity or you can build your own rules with individual actions.
To open the activity rule builder, navigate to Correlation > Manage Rules > Activity Rules > Create Activity Rule.
Each action in a activity rule corresponds to a log. Logs contain various fields, and each field has a specific value. With advanced options (found under Filters on the right of the action), you can provide filter criteria for each field of the log/action and specify a threshold limit on the minimum number of repetitions of the action.
Note: When you provide more than one value for an equals comparison, the set of values provided are treated as a list of possible values and the action is accepted if any one value from the list is true. The same holds true for the contains, starts with, and ends with comparisons.When you provide more than one not equals comparison, the set of values provided need to hold true for the action to be accepted.
The link to comparison type is used to check the value of the selected field against the value of a field in another action (belonging to the same rule or the primary action of the other rule). For instance, if the field Device type of Action 1 is linked to Action 2's Device type value, then Action 1 would get triggered only if the value of both the linked fields are the same.
When you choose link to, the icon appears at the end of the filter. Clicking on the icon will present a new tab.
Click the check box corresponding to the field of the second action against which you want to compare the value of the previous action. Click OK to complete linking the two actions.
The is constant option is used to treat the specific field as constant. By selecting this option, a set of repeated actions are accepted by the rule only if this field's value remains constant throughout all the iterations. For instance, if the Target User field is kept as constant, then the action gets triggered only when the value of this field remains constant in all the iterations. The action doesn't get triggered if the event is generated with different values.
EventLog Analyzer's Activity Monitoring Reports provide information on Windows, Unix and VPN Sessions. The reports provide details such as Device name, Username, Start Time, End Time, Status, and Duration.
The calendar widget allows you to select the time period for which you want to review the session activity for the selected devices/users. You can also schedule an activity monitoring report. The activity monitoring report can be exported in the PDF and CSV formats, by clicking Export as.
To know more details of a particular session, you can click on View History. This tab displays all the details as given below:
This page contains the Configure Fields and Advanced View tabs. The Configure Fields tab allows you to view similar logs generated in a session by extracting logs that have the same field value (Domain, Device Name, Logon ID, and Username). You can choose the field by which you want to retrieve logs by clicking on the desired options from the drop-down box. By clicking on the Advanced View tab, you can drill down and view the raw logs of that session.
EventLog Analyzer allows you to view the Activity Monitoring Reports for Windows, Unix, and VPN Sessions based on users and devices in the form of User-Based View and Device-Based View, in addition to the default view.
In the User-based view, you can analyze the weekly login and logout activities of a particular user. You can hover your mouse pointer over a generated user-based report in the table to find the Weekly Login View tab. Clicking on this tab displays a timeline graph for every day of the week in which you can view a particular user's active session duration, login time, and logout time for any given day. This view also provides the number of hours the user was active per day and for the entire week. The Weekly Login View report is available only for all system-generated reports.
Copyright © 2020, ZOHO Corp. All Rights Reserved.