Event Log Settings
NAVIGATION Agent > Agents > Event Log Settings
The Event Log Settings page specifies the combination of event log types and categories that are collected by the VSA.
NOTE Alerts can be separately specified for events using Monitoring > Event Log Alerts. If NO or ALL event logs types and categories are collected for a machine, then event log alerts are generated for that machine. If SOME event log types and categories are collected for a machine, then event log alerts are generated only for those event log types.
To specify Event Log Settings:
- Click an event log type in the Event Log Types list box. Hold down the [Ctrl] key to click multiple event log types.
- Click Add > to add event log types to the Assigned Event Types list box. Click << Remove or << Remove all to remove event log types from the Assigned Event Types list box.
- Check one or more event categories: Error, Warning, Information, Success Audit, Failure Audit, Critical, Verbose.
- Select one or more machine IDs.
- Click Update or Replace to apply these settings to selected machine IDs.
Global Event Log Black Lists
Each agent processes all events, however events listed on a "black list" are not uploaded to the VSA server. There are two black lists. One is updated periodically by Kaseya and is named EvLogBlkList.xml.
The second one, named EvLogBlkListEx.xml
, can be maintained by the service provider and is not updated by Kaseya. Both are located in the \Kaseya\WebPages\ManagedFiles\VSAHiddenFiles
directory. Alarm detection and processing operates regardless of whether entries are on the collection blacklist.
Flood Detection
If 1000 events—not counting black list events—are uploaded to the Kaseya Server by an agent within one hour, further collection of events of that log type are stopped for the remainder of that hour. A new event is inserted into the event log to record that collection was suspended. At the end of the hour, collection automatically resumes. This prevents short term heavy loads from swamping your Kaseya Server. Alarm detection and processing operates regardless of whether collection is suspended.
Update
Adds event log types listed in the Assigned Event Types list box to the set of event log types already assigned to selected machine IDs.
Replace
Replaces all event log types assigned to selected machine IDs with the event log types listed in the Assigned Event Types list.
Clear All
Clears all event log types assigned to selected machine IDs.
Select All/Unselect All
Click the Select All link to check all rows on the page. Click the Unselect All link to uncheck all rows on the page.
Check-in status
These icons indicate the agent check-in status of each managed machine. Hovering the cursor over a check-in icon displays the agent Quick View window.
User Logged In and Agent is Active
User Logged In and Agent is Inactive
User Not Logged In and Agent is online
User Not Logged In and Agent is Idle
Machine.Group ID
The list of Machine.Group IDs displayed is based on the Machine ID / Group ID filter and the machine groups the user is authorized to see using System > User Security > Scopes.
Delete Icon
Click the delete icon to delete this record.
Edit icon
Click the edit icon next to a machine ID to automatically set header parameters to those matching the selected machine ID.
Assigned Categories
The event categories stored by the VSA for this machine ID and event log:
- Error
- Warning
- Information
- Success Audit
- Failure Audit
- Critical
- Verbose