How to create a policy to monitor NT Events
|Article:HOWTO30287|||||Created: 2010-06-16|||||Updated: 2011-04-29|||||Article URL http://www.symantec.com/docs/HOWTO30287|
How to create a policy to monitor NT events
- Right click on the folder where the policy will be stored and select New > Monitor Policy (Agent-Based)
- Go to the new policy and give it a name
- On the Rules tab click the blue plus icon
- Click the New icon and select 'NT Event"
- Give the new rule a name and select a category for this rule
- Click the yellow wheel icon to create a new Metric
- Depending on the event information desired, select the appropriate type on 'Property'
- Select the Condition type and the value to monitor
- Click OK
- Configure the Repeat as desired
- Configure any Actions desired
- Note: You can configure Actions on the rule and/or the policy. If you want the rule to trigger an alert or action, configure it from this screen.
- Click OK
- Ensure the new rule is selected and click OK
- Configure the Detection tab as desired or leave it blank
- Configure the Action tab as desired
- At the bottom of the window, select the target(s) for the policy
- Save Changes
- Once the agents have downloaded a new configuration, the Monitor Agent will start monitoring the requested NT Events
Article URL http://www.symantec.com/docs/HOWTO30287