<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Installation &#8211; Blue Lance</title>
	<atom:link href="https://bluelance.com/docs-category/eventlogcentral/installation/feed/" rel="self" type="application/rss+xml" />
	<link>https://bluelance.com</link>
	<description></description>
	<lastBuildDate>Thu, 04 Jun 2026 23:07:03 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://bluelance.com/wp-content/uploads/2025/11/fevicon-ic-1.png</url>
	<title>Installation &#8211; Blue Lance</title>
	<link>https://bluelance.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Prerequisites</title>
		<link>https://bluelance.com/docs/prerequisites/</link>
		
		<dc:creator><![CDATA[peter thomas]]></dc:creator>
		<pubDate>Tue, 02 Jun 2026 23:22:23 +0000</pubDate>
				<guid isPermaLink="false">https://bluelance.com/?post_type=docs&#038;p=16191</guid>

					<description><![CDATA[Before installing EventLogCentral, confirm that your environment meets the following requirements for both the EventLogCentral server and the EventLogAgent clients that will be deployed to monitored systems. EventLogCentral Server requirements: Requirement Details Operating System Windows Server 2019 or newer Browser Chrome, Firefox, Microsoft Edge, or Safari Privileges Local administrator account required Network Network connectivity to [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Before installing EventLogCentral, confirm that your environment meets the following requirements for both the EventLogCentral server and the EventLogAgent clients that will be deployed to monitored systems.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>EventLogCentral Server requirements:</strong></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>Requirement</strong></td><td><strong>Details</strong></td></tr><tr><td>Operating System</td><td>Windows Server 2019 or newer</td></tr><tr><td>Browser</td><td>Chrome, Firefox, Microsoft Edge, or Safari</td></tr><tr><td>Privileges</td><td>Local administrator account required</td></tr><tr><td>Network</td><td>Network connectivity to all managed EventLogAgent clients</td></tr><tr><td>IP Address</td><td>Static IP address or DNS hostname recommended for production deployments</td></tr></tbody></table></figure>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>EventLogAgent client requirements:</strong></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>Requirement</strong></td><td><strong>Details</strong></td></tr><tr><td>Operating System</td><td>Windows Server 2016 or newer, Windows 10, or Windows 11</td></tr><tr><td>Privileges</td><td>Local administrator account required for installation</td></tr><tr><td>Network</td><td>Outbound connectivity to the EventLogCentral server on port 52966</td></tr></tbody></table></figure>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Network requirements:</strong></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>Port</strong></td><td><strong>Protocol</strong></td><td><strong>Direction</strong></td><td><strong>Purpose</strong></td></tr><tr><td>52965</td><td>HTTP</td><td>Inbound to server</td><td>EventLogCentral web UI (non-secure)</td></tr><tr><td>52966</td><td>HTTPS</td><td>Inbound to server</td><td>EventLogCentral web UI and agent communication (recommended)</td></tr><tr><td>514</td><td>UDP/TCP</td><td>Outbound from agents</td><td>Default syslog forwarding to LT Auditor <sup>MP</sup> or other targets</td></tr><tr><td>6514</td><td>TCP/TLS</td><td>Outbound from agents</td><td>Secure syslog forwarding to LT Auditor <sup>MP</sup> or other targets</td></tr></tbody></table></figure>



<p class="wp-block-paragraph"><em>[Your administrator should confirm the exact ports required in your environment and ensure firewall rules are in place before proceeding with installation.]</em></p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Download packages:</strong></p>



<p class="wp-block-paragraph">Two separate installation packages are required — one for the EventLogCentral server and one for the EventLogAgent clients:</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>Package</strong></td><td><strong>Purpose</strong></td></tr><tr><td>lta-mp-eventlogcentral.zip</td><td>EventLogCentral server installation</td></tr><tr><td>lta-mp-eventlogagent.zip</td><td>EventLogAgent client installation</td></tr></tbody></table></figure>



<p class="wp-block-paragraph"><em>[Your administrator should confirm where to obtain the current installation packages for your environment.]</em></p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>SSL certificate considerations:</strong></p>



<p class="wp-block-paragraph">EventLogCentral automatically generates a self-signed TLS certificate during server installation. If self-signed certificates are used:</p>



<ul class="wp-block-list">
<li>The public certificate file (ltaeventlog.cer) must be distributed to all EventLogAgent client machines so agents can trust the EventLogCentral server certificate</li>



<li>Alternatively, a custom TLS certificate can be installed on the server — see the Installing EventLogCentral Server article for details</li>
</ul>



<p class="wp-block-paragraph">If your organization requires a trusted CA-signed certificate rather than the auto-generated self-signed certificate, prepare the certificate before beginning installation.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>LT Auditor <sup>MP</sup> requirements:</strong></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>Requirement</strong></td><td><strong>Details</strong></td></tr><tr><td>LT Auditor <sup>MP</sup> Server</td><td>Must be installed and running</td></tr><tr><td>Syslog Listener</td><td>Must be active and configured to receive EventLogCentral forwarded events</td></tr></tbody></table></figure>



<p class="wp-block-paragraph"><em>[Your administrator should confirm the LT Auditor <sup>MP</sup> syslog listener port and protocol before configuring forwarding targets in EventLogCentral.]</em></p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Prerequisites checklist:</strong></p>



<ul class="wp-block-list">
<li>[ ] EventLogCentral server meets Windows Server 2019 or newer requirement</li>



<li>[ ] Static IP address or DNS hostname is assigned to the EventLogCentral server</li>



<li>[ ] Required firewall ports are open between agents and the EventLogCentral server</li>



<li>[ ] LT Auditor <sup>MP</sup> server is installed and running with syslog listener active</li>



<li>[ ] Both installation packages are available</li>



<li>[ ] SSL certificate approach is decided — self-signed or custom CA certificate</li>



<li>[ ] Local administrator credentials are available on the server and all agent machines</li>
</ul>



<p class="wp-block-paragraph"><em>[Your administrator should complete this checklist before proceeding to the installation articles.]</em></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Installing EventLogCentral Server</title>
		<link>https://bluelance.com/docs/installing-server/</link>
		
		<dc:creator><![CDATA[peter thomas]]></dc:creator>
		<pubDate>Tue, 02 Jun 2026 23:19:59 +0000</pubDate>
				<guid isPermaLink="false">https://bluelance.com/?post_type=docs&#038;p=16187</guid>

					<description><![CDATA[This article covers the installation of the EventLogCentral server component. The server hosts the web-based administrative interface and manages configuration for all EventLogAgent clients in your environment. Complete this installation before deploying any EventLogAgent clients. Step 1 — Download and prepare the installation package: Download the following installation package: lta-mp-eventlogcentral.zip If the ZIP file was [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">This article covers the installation of the EventLogCentral server component. The server hosts the web-based administrative interface and manages configuration for all EventLogAgent clients in your environment. Complete this installation before deploying any EventLogAgent clients.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Step 1 — Download and prepare the installation package:</strong></p>



<p class="wp-block-paragraph">Download the following installation package:</p>



<p class="wp-block-paragraph">lta-mp-eventlogcentral.zip</p>



<p class="wp-block-paragraph">If the ZIP file was downloaded from the internet:</p>



<ol class="wp-block-list">
<li>Right-click the ZIP file</li>



<li>Select <strong>Properties</strong></li>



<li>Click <strong>Unblock</strong> if present</li>



<li>Click <strong>Apply</strong></li>
</ol>



<p class="wp-block-paragraph">Extract the contents of the ZIP file to a temporary folder.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Step 2 — Run the installer:</strong></p>



<p class="wp-block-paragraph">Locate the installer in the extracted folder:</p>



<p class="wp-block-paragraph">LTA_EventLogCentral.msi</p>



<p class="wp-block-paragraph">Right-click the MSI file and select <strong>Install</strong>. Follow the installation wizard prompts to complete the installation.</p>



<p class="wp-block-paragraph">By default, the application installs to:</p>



<p class="wp-block-paragraph">C:\Program Files\Blue Lance 2-0\LTA_EventLogCentral</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Step 3 — SSL certificate:</strong></p>



<p class="wp-block-paragraph">During installation, EventLogCentral automatically generates a self-signed TLS certificate:</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>File</strong></td><td><strong>Location</strong></td><td><strong>Purpose</strong></td></tr><tr><td>ltaeventlog.pfx</td><td>C:\Program Files\Blue Lance 2-0\certs</td><td>Server TLS certificate used for HTTPS and agent communication</td></tr><tr><td>ltaeventlog.cer</td><td>C:\Program Files\Blue Lance 2-0\certs</td><td>Public certificate file — must be distributed to all EventLogAgent client machines when using self-signed certificates</td></tr></tbody></table></figure>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Using a custom TLS certificate:</strong></p>



<p class="wp-block-paragraph">If your organization requires a custom CA-signed certificate instead of the auto-generated self-signed certificate:</p>



<ol class="wp-block-list">
<li>Replace the existing certificate file in the certs folder with your custom certificate</li>



<li>Ensure the certificate:
<ul class="wp-block-list">
<li>Supports Server Authentication</li>



<li>Matches the server hostname or DNS name</li>
</ul>
</li>



<li>If the replacement certificate is password protected, update the following Windows environment variable with the certificate password:</li>
</ol>



<p class="wp-block-paragraph">LTAEVENTLOG_CERT_PASSWORD</p>



<ol start="4" class="wp-block-list">
<li>If the replacement certificate uses a different filename, update the appsettings.json file:
<ul class="wp-block-list">
<li>Locate the https:certificate setting</li>



<li>Update the value to reference the new certificate filename</li>
</ul>
</li>



<li>Restart the <strong>LT Auditor <sup>MP</sup> Event Log Server Service</strong> to apply the certificate changes</li>
</ol>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Step 4 — Verify the installation:</strong></p>



<p class="wp-block-paragraph">After installation completes:</p>



<ol class="wp-block-list">
<li>Open a browser on the server</li>



<li>Navigate to:</li>
</ol>



<figure class="wp-block-embed"><div class="wp-block-embed__wrapper">
https://&lt;server-name>:52966
</div></figure>



<ol start="3" class="wp-block-list">
<li>Confirm the EventLogCentral login page appears</li>



<li>Confirm the <strong>LT Auditor <sup>MP</sup> Event Log Server Service</strong> is running:</li>
</ol>



<p class="wp-block-paragraph">sc query &#8220;LT Auditor-MP Event Log Server Service&#8221;</p>



<p class="wp-block-paragraph">The service should show as <strong>Running</strong>.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Step 5 — First time login:</strong></p>



<p class="wp-block-paragraph">On first access, log in using the default administrator credentials:</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>Field</strong></td><td><strong>Value</strong></td></tr><tr><td>Username</td><td>admin</td></tr><tr><td>Password</td><td>TempP@ssw0rd!2025</td></tr></tbody></table></figure>



<p class="wp-block-paragraph">Change the default password immediately after first login. Refer to the Admin article for instructions on changing the administrator password.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Reviewing server logs:</strong></p>



<p class="wp-block-paragraph">If the application fails to start or clients cannot connect after installation, review the logs located in:</p>



<p class="wp-block-paragraph">C:\Program Files\Blue Lance 2-0\LTA_EventLogCentral\logs</p>



<p class="wp-block-paragraph">Check for:</p>



<ul class="wp-block-list">
<li>Certificate loading failures</li>



<li>Port conflicts on 52965 or 52966</li>



<li>Database connectivity errors</li>



<li>TLS negotiation failures</li>



<li>Service startup issues</li>
</ul>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Password requirements:</strong></p>



<p class="wp-block-paragraph">When changing the default password or creating new user accounts, passwords must meet the following requirements:</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>Requirement</strong></td><td><strong>Detail</strong></td></tr><tr><td>Minimum length</td><td>10 characters</td></tr><tr><td>Uppercase letters</td><td>At least one (A-Z)</td></tr><tr><td>Lowercase letters</td><td>At least one (a-z)</td></tr><tr><td>Digits</td><td>At least one (0-9)</td></tr><tr><td>Special characters</td><td>At least one (!@#$%^&amp;*)</td></tr></tbody></table></figure>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Installing EventLogAgent</title>
		<link>https://bluelance.com/docs/installing-agent/</link>
		
		<dc:creator><![CDATA[peter thomas]]></dc:creator>
		<pubDate>Tue, 02 Jun 2026 23:20:38 +0000</pubDate>
				<guid isPermaLink="false">https://bluelance.com/?post_type=docs&#038;p=16189</guid>

					<description><![CDATA[EventLogAgent is the lightweight Windows service deployed on each server or workstation you want to monitor. Each agent connects to the EventLogCentral server to retrieve its assigned configuration and forwards collected events directly to LT Auditor MP or the configured syslog destination. The agent must be installed individually on every Windows machine in scope for [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">EventLogAgent is the lightweight Windows service deployed on each server or workstation you want to monitor. Each agent connects to the EventLogCentral server to retrieve its assigned configuration and forwards collected events directly to LT Auditor <sup>MP</sup> or the configured syslog destination. The agent must be installed individually on every Windows machine in scope for monitoring.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Prerequisites:</strong></p>



<p class="wp-block-paragraph">Before installing the agent, confirm the following:</p>



<ul class="wp-block-list">
<li>The EventLogCentral server is installed and running</li>



<li>The EventLogCentral login page is accessible at https://&lt;server-name&gt;:52966</li>



<li>If using self-signed certificates, the ltaeventlog.cer file has been copied from the EventLogCentral server and is available on the agent machine</li>



<li>Local administrator privileges are available on the target machine</li>
</ul>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Step 1 — Download and prepare the installation package:</strong></p>



<p class="wp-block-paragraph">Download the following installation package:</p>



<p class="wp-block-paragraph">lta-mp-eventlogagent.zip</p>



<p class="wp-block-paragraph">If the ZIP file was downloaded from the internet:</p>



<ol class="wp-block-list">
<li>Right-click the ZIP file</li>



<li>Select <strong>Properties</strong></li>



<li>Click <strong>Unblock</strong> if present</li>



<li>Click <strong>Apply</strong></li>
</ol>



<p class="wp-block-paragraph">Extract the contents of the ZIP file to a temporary folder.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Step 2 — Run the installer:</strong></p>



<p class="wp-block-paragraph">Locate the installer in the extracted folder:</p>



<p class="wp-block-paragraph">LTA_EventLogAgent.msi</p>



<p class="wp-block-paragraph">Right-click the MSI file and select <strong>Run as Administrator</strong>.</p>



<p class="wp-block-paragraph">The installation runs silently and installs to the default location:</p>



<p class="wp-block-paragraph">C:\Program Files\Blue Lance 2-0\LTA_EventLogAgent</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Step 3 — Configure the agent:</strong></p>



<p class="wp-block-paragraph">After installation, update the agent configuration file:</p>



<p class="wp-block-paragraph">C:\Program Files\Blue Lance 2-0\LTA_EventLogAgent\appsettings.json</p>



<p class="wp-block-paragraph">Locate and update the following setting:</p>



<p class="wp-block-paragraph">&#8220;ServerUrl&#8221;: &#8220;https://&lt;server-address&gt;:52966&#8221;</p>



<p class="wp-block-paragraph">Replace &lt;server-address&gt; with the hostname or IP address of your EventLogCentral server.</p>



<p class="wp-block-paragraph">The agent uses this URL to:</p>



<ul class="wp-block-list">
<li>Retrieve audit configuration updates</li>



<li>Download audit policies</li>



<li>Receive forwarding instructions</li>



<li>Synchronize group assignments</li>
</ul>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Step 4 — Configure self-signed certificate trust:</strong></p>



<p class="wp-block-paragraph">If the EventLogCentral server is using the auto-generated self-signed certificate, the agent must be configured to trust it before it can communicate with the server.</p>



<ol class="wp-block-list">
<li>Copy the following file from the EventLogCentral server to the agent machine:</li>
</ol>



<p class="wp-block-paragraph">ltaeventlog.cer</p>



<ol start="2" class="wp-block-list">
<li>Place the file in the following folder on the agent machine:</li>
</ol>



<p class="wp-block-paragraph">C:\Program Files\Blue Lance 2-0\LTA_EventLogAgent\certs</p>



<ol start="3" class="wp-block-list">
<li>Open an elevated PowerShell window and run the following script:</li>
</ol>



<p class="wp-block-paragraph">.\Install-Rootcert.ps1</p>



<p class="wp-block-paragraph">The script imports the certificate into:</p>



<p class="wp-block-paragraph">Cert:\LocalMachine\Root</p>



<p class="wp-block-paragraph">This allows the EventLogAgent service to trust the EventLogCentral server certificate.</p>



<p class="wp-block-paragraph">If your organization uses a custom CA-signed certificate on the EventLogCentral server, this step may not be required — confirm with your administrator.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Step 5 — Restart the agent service:</strong></p>



<p class="wp-block-paragraph">After updating the configuration file and installing the certificate, restart the EventLogAgent service to apply the changes:</p>



<p class="wp-block-paragraph">Restart-Service LTA_EventLogAgent</p>



<p class="wp-block-paragraph">Or restart via the Services console (services.msc):</p>



<ol class="wp-block-list">
<li>Locate <strong>LT Auditor <sup>MP</sup> Event Log Agent Service</strong></li>



<li>Click <strong>Restart</strong></li>
</ol>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Step 6 — Verify agent registration:</strong></p>



<p class="wp-block-paragraph">After the service starts, confirm the agent has successfully registered with the EventLogCentral server:</p>



<ol class="wp-block-list">
<li>Log in to the EventLogCentral web interface at https://&lt;server-name&gt;:52966</li>



<li>Navigate to <strong>Clients</strong> in the left navigation menu</li>



<li>Confirm the new agent appears in the client list</li>



<li>Confirm the client status shows <strong>Online</strong></li>
</ol>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Reviewing agent logs:</strong></p>



<p class="wp-block-paragraph">If the agent does not appear in the EventLogCentral client list or shows as offline, review the agent log files:</p>



<p class="wp-block-paragraph">C:\Program Files\Blue Lance 2-0\LTA_EventLogAgent\logs</p>



<p class="wp-block-paragraph">Verify the logs show:</p>



<ul class="wp-block-list">
<li>Successful server connection</li>



<li>Configuration synchronization</li>



<li>Group assignment retrieval</li>



<li>Event forwarding initialization</li>
</ul>



<p class="wp-block-paragraph">Review logs for:</p>



<ul class="wp-block-list">
<li>TLS or certificate errors</li>



<li>Connectivity failures to the EventLogCentral server</li>



<li>Authentication errors</li>



<li>Configuration synchronization issues</li>
</ul>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Deploying agents across multiple machines:</strong></p>



<p class="wp-block-paragraph">The EventLogAgent must be installed individually on each Windows machine you want to monitor. For large deployments, consider using one of the following methods to automate agent installation:</p>



<ul class="wp-block-list">
<li><strong>Group Policy</strong> — distribute the MSI package via Group Policy software installation</li>



<li><strong>SCCM / Microsoft Endpoint Manager</strong> — deploy the MSI package as an application</li>



<li><strong>Other enterprise deployment tools</strong> — use supported MSI command line parameters for silent installation</li>
</ul>



<p class="wp-block-paragraph"><em>[Your administrator should document the deployment method used in your environment and the MSI parameters used for silent or automated installations.]</em></p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Account lockout policy:</strong></p>



<p class="wp-block-paragraph">Be aware of the following security settings that apply to the EventLogCentral web interface:</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>Setting</strong></td><td><strong>Value</strong></td></tr><tr><td>Failed login attempts before lockout</td><td>5</td></tr><tr><td>Lockout duration</td><td>15 minutes</td></tr><tr><td>Session inactivity timeout</td><td>60 minutes</td></tr></tbody></table></figure>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
