<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>file system activity &#8211; Blue Lance</title>
	<atom:link href="https://bluelance.com/docs-tag/file-system-activity/feed/" rel="self" type="application/rss+xml" />
	<link>https://bluelance.com</link>
	<description></description>
	<lastBuildDate>Thu, 04 Jun 2026 23:13:36 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://bluelance.com/wp-content/uploads/2025/11/fevicon-ic-1.png</url>
	<title>file system activity &#8211; Blue Lance</title>
	<link>https://bluelance.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Day-to-Day Administration</title>
		<link>https://bluelance.com/docs/day-to-day-admin/</link>
		
		<dc:creator><![CDATA[peter thomas]]></dc:creator>
		<pubDate>Thu, 28 May 2026 16:20:14 +0000</pubDate>
				<guid isPermaLink="false">https://bluelance.com/?post_type=docs&#038;p=15862</guid>

					<description><![CDATA[EventLogCentral is a management platform rather than a monitoring interface — day-to-day monitoring of collected events happens in LT Auditor MP. Day-to-day administration in EventLogCentral focuses on keeping agents healthy, configurations current, and forwarding targets active. This article covers the routine tasks administrators should perform regularly to keep EventLogCentral running smoothly. Checking agent status: The [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">EventLogCentral is a management platform rather than a monitoring interface — day-to-day monitoring of collected events happens in LT Auditor <sup>MP</sup>. Day-to-day administration in EventLogCentral focuses on keeping agents healthy, configurations current, and forwarding targets active. This article covers the routine tasks administrators should perform regularly to keep EventLogCentral running smoothly.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Checking agent status:</strong></p>



<p class="wp-block-paragraph">The Clients page is the primary health dashboard for EventLogCentral. Check it regularly to confirm all expected agents are online and reporting.</p>



<ol class="wp-block-list">
<li>Navigate to <strong>Clients</strong> in the left navigation menu</li>



<li>Review the <strong>Status</strong> column for each client:
<ul class="wp-block-list">
<li><strong>Online</strong> — the agent is running and checking in normally</li>



<li><strong>Offline</strong> — the agent has not checked in recently</li>
</ul>
</li>



<li>Review the <strong>Last Heartbeat</strong> column to identify agents that have not reported recently even if they show as Online</li>



<li>Use the search bar to filter by group name or machine name when managing large environments</li>
</ol>



<p class="wp-block-paragraph">If any agent shows as Offline:</p>



<p class="wp-block-paragraph">Confirm the EventLogAgent service is running on that machine:<br>sc query LTA_EventLogAgent</p>



<ul class="wp-block-list">
<li></li>



<li>Confirm network connectivity between the agent and the EventLogCentral server</li>
</ul>



<p class="wp-block-paragraph">Review the agent logs for errors:<br>C:\Program Files\Blue Lance 2-0\LTA_EventLogAgent\logs</p>



<ul class="wp-block-list">
<li></li>
</ul>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Verifying effective configuration:</strong></p>



<p class="wp-block-paragraph">After making configuration changes to a group, verify that the correct configuration has been applied to individual clients:</p>



<ol class="wp-block-list">
<li>Navigate to <strong>Clients</strong></li>



<li>Click on the client name</li>



<li>Click <strong>View Effective Configuration</strong></li>



<li>Confirm the following are correctly reflected:
<ul class="wp-block-list">
<li>Applied audit policies</li>



<li>Event log collection settings</li>



<li>File audit rules</li>



<li>Assigned forwarding target</li>
</ul>
</li>
</ol>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Forcing a configuration sync:</strong></p>



<p class="wp-block-paragraph">By default, agents retrieve configuration updates from EventLogCentral on their next heartbeat cycle (default: every 5 minutes). If a configuration change needs to be applied immediately:</p>



<ol class="wp-block-list">
<li>Navigate to <strong>Clients</strong></li>



<li>Locate the relevant client</li>



<li>Click the <strong>⋮</strong> menu</li>



<li>Select <strong>Force Configuration Sync</strong></li>
</ol>



<p class="wp-block-paragraph">The agent will retrieve and apply the latest configuration immediately rather than waiting for the next scheduled heartbeat.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Reassigning a client to a different group:</strong></p>



<p class="wp-block-paragraph">If a machine&#8217;s role changes and it needs to be moved to a different group:</p>



<ol class="wp-block-list">
<li>Navigate to <strong>Clients</strong></li>



<li>Locate the client to reassign</li>



<li>Click the <strong>⋮</strong> menu</li>



<li>Select <strong>Reassign Group</strong></li>



<li>Select the new group from the available list</li>



<li>Confirm the reassignment</li>
</ol>



<p class="wp-block-paragraph">The client will receive the new group&#8217;s configuration — including audit policies, event log settings, file audit rules, and sender assignment — on its next heartbeat cycle.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Testing target connectivity:</strong></p>



<p class="wp-block-paragraph">Periodically confirm that all configured syslog targets are reachable to ensure event forwarding is not silently failing:</p>



<ol class="wp-block-list">
<li>Navigate to <strong>Targets</strong></li>



<li>For each configured target, click the <strong>⋮</strong> menu</li>



<li>Select <strong>Test Connection</strong></li>



<li>Review the test result — confirm the target is reachable</li>



<li>If a target test fails:
<ul class="wp-block-list">
<li>Confirm the syslog server is running and accepting connections</li>



<li>Confirm no firewall is blocking outbound traffic on the configured port</li>



<li>Confirm the server address and port are correct in the target configuration</li>
</ul>
</li>
</ol>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Reviewing configuration change history:</strong></p>



<p class="wp-block-paragraph">EventLogCentral maintains an audit log of configuration changes made to each client. Use this to review what changes have been made and when:</p>



<ol class="wp-block-list">
<li>Navigate to <strong>Clients</strong></li>



<li>Click the <strong>⋮</strong> menu next to the relevant client</li>



<li>Select <strong>View Audit Log</strong></li>



<li>Review the history of configuration changes with timestamps</li>
</ol>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Routine administration checklist:</strong></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>Frequency</strong></td><td><strong>Task</strong></td></tr><tr><td>Daily</td><td>Check the Clients page — confirm all expected agents are Online and Last Heartbeat timestamps are current</td></tr><tr><td>Daily</td><td>Review LT Auditor <sup>MP</sup> View for expected event flow from EventLogCentral sources</td></tr><tr><td>Weekly</td><td>Test connectivity to all configured targets</td></tr><tr><td>Weekly</td><td>Review any clients that have been Offline and investigate if unresolved</td></tr><tr><td>Monthly</td><td>Review group configurations — confirm audit policies, event log settings, and file audit rules are still appropriate</td></tr><tr><td>Monthly</td><td>Review user accounts in Admin — confirm access is appropriate and no stale accounts exist</td></tr><tr><td>As needed</td><td>Force Configuration Sync after urgent policy changes</td></tr><tr><td>As needed</td><td>Reassign clients to correct groups after machine role changes</td></tr></tbody></table></figure>



<p class="wp-block-paragraph"><em>[Your administrator should assign ownership of routine administration tasks to specific team members and document the results of regular checks so the administration history is auditable.]</em></p>



<p class="wp-block-paragraph"></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
