Next Topic

Previous Topic

Book Contents

Event Log Settings

The Event Log Settings page specifies the combination of event log types and categories that are collected by the VSA.

Note: Alerts can be separately specified for events using Monitoring > Event Log Alerts. If NO or ALL event logs types and categories are collected for a machine, then event log alerts are generated for that machine. If SOME event log types and categories are collected for a machine, then NO event log alerts are generated.

To specify Event Log Settings:

  1. Click an event log type in the Event Log Types list box. Hold down the [Ctrl] key to click multiple event log types.
  2. Click Add > to add event log types to the Assigned Event Types list box. Click << Remove or << Remove all to remove event log types from the Assigned Event Types list box.
  3. Check one or more event categories: Error, Warning, Information, Success Audit, Failure Audit, Critical, Verbose.
  4. Select one or more machine IDs.
  5. Click Update or Replace to apply these settings to selected machine IDs.

Global Event Log Black Lists

Each agent processes all events, however events listed on a "black list" are not uploaded to the VSA server. There are two black lists. One is updated periodically by Kaseya and is named EvLogBlkList.xml. The second one, named EvLogBlkListEx.xml, can be maintained by the service provider and is not updated by Kaseya. Both are located in the \Kaseya\WebPages\ManagedFiles\VSAHiddenFiles directory. Alarm detection and processing operates regardless of whether entries are on the collection blacklist.

Flood Detection

If 1000 events—not counting black list events—are uploaded to the Kaseya Server by an agent within one hour, further collection of events of that log type are stopped for the remainder of that hour. A new event is inserted into the event log to record that collection was suspended. At the end of the hour, collection automatically resumes. This prevents short term heavy loads from swamping your Kaseya Server. Alarm detection and processing operates regardless of whether collection is suspended.

Update

Adds event log types listed in the Assigned Event Types list box to the set of event log types already assigned to selected machine IDs.

Replace

Replaces all event log types assigned to selected machine IDs with the event log types listed in the Assigned Event Types list.

Clear All

Clears all event log types assigned to selected machine IDs.

Select All/Unselect All

Click the Select All link to check all rows on the page. Click the Unselect All link to uncheck all rows on the page.

Check-in status

These icons indicate the agent check-in status of each managed machine. Hovering the cursor over a check-in icon displays the agent Quick View window.

Word 50% / HTML 50% Online but waiting for first audit to complete

Word 50% / HTML 50% Agent online

Word 50% / HTML 50% Agent online and user currently logged on.

Word 50% / HTML 50% Agent online and user currently logged on, but user not active for 10 minutes

Word 50% / HTML 50% Agent is currently offline

Word 50% / HTML 50% Agent has never checked in

Word 50% / HTML 50% Agent is online but remote control has been disabled

Word 50% / HTML 50% The agent has been suspended

Word 80% / HTML 80% An agent icon adorned with a red clock badge is a temporary agent.

Machine.Group ID

The list of Machine.Group IDs displayed is based on the Machine ID / Group ID filter and the machine groups the user is authorized to see using System > User Security > Scopes.

Delete Icon

Click the delete icon to delete this record.

Edit icon

Click the edit icon next to a machine ID to automatically set header parameters to those matching the selected machine ID.

Assigned Categories

The event categories stored by the VSA for this machine ID and event log: