This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Gather Change Auditor events

Hello all,

I would like to ask if someone can provide a very high level bullets style guide with all the necessary steps on how i can gather and report events from CA. For example:

  • Install InTrust agent at CA server
  • From the InTrust manager go to Sites and configure the "All Change Auditor Coordinator computers"
  • ...
  • ...

Thank you.

Parents
  • InTrust can collect any native Windows Event Log, including CA Windows Event Log generated by CA Agent on the audited Windows Server.
    (example) Audit DC. CAAD Agent is installed on DC. The CA agent settings turned on to generate generates CAAD Windows Event Log.
    InTrust Agent collects CAAD Windows Event Log (alone with Security, System, Application event logs etc.) into \\Share\Repository for Long term storage "untampered platform log"
    Now you can view the \\Repository via (a) InTrust Repository Viewer UI - raw Event Log, (b) ITSearch UI (analytics etc.) .
Reply
  • InTrust can collect any native Windows Event Log, including CA Windows Event Log generated by CA Agent on the audited Windows Server.
    (example) Audit DC. CAAD Agent is installed on DC. The CA agent settings turned on to generate generates CAAD Windows Event Log.
    InTrust Agent collects CAAD Windows Event Log (alone with Security, System, Application event logs etc.) into \\Share\Repository for Long term storage "untampered platform log"
    Now you can view the \\Repository via (a) InTrust Repository Viewer UI - raw Event Log, (b) ITSearch UI (analytics etc.) .
Children
No Data