ELM - Enterprise Manager 
Event Log Monitor
ELM
Enterprise Manager gives you the power to see the health and status
of your distributed systems with a single glance.
ELM Enterprise Manager is designed to monitor Windows
NT, Windows 2000, and Windows XP computers in real-time. It is a
client/server application that automates a variety of the administrative
functions required for monitoring and managing Windows-based servers
and TCP/IP systems and devices. ELM Enterprise Manager is essentially
a rules-based management system (RBMS). Using filters and rules,
you decide which events and conditions trigger notification or corrective
action. In addition to executing Notification Methods, ELM Enterprise
Manager also includes data archiving and reporting, and a flexible
and easy-to-use interface.
There are two subset companion Products for ELM Enterprise Manager
which are:
ELM Log Manager and
ELM Performance Manager.
ELM Enterprise Manager is a superset of ELM Performance Manager
and ELM Log Manager containing all the features of the other two
and more besides. To compare the three, here is a product comparison
grid. 
PRACTICAL APPLICATIONS:
- Cross-Platform - send and receive SNMP traps, monitor
SNMP Object IDs and send and receive Syslog Messages
- Security - can help you monitor your network's security
perimeters, keeping a close watch on your sensitive file servers,
and help you to maintain your security boundaries
- Microsoft .NET Servers - .NET is Microsoft's platform
for a set of XML Web services that represent the next generation
of software from Microsoft.
MONITOR ITEMS:
- Event Logs using one of two monitor items:
- Event Alarm. If you are using an Event Alarm, the
Agent compares the new event with the Event Alarm criteria.
If the event matches the criteria the specified number of
times within the specified time period, the Action on the
Event Found tab is executed. If the event is not found the
specified number of times within the specified time period,
the Action(s) on the Event Not Found tab is/are executed.
- Event Collector. This Monitor Item collects all events
matching the specified Event Filter(s) from the monitored
Agents.
- Health and Performance - monitoring performance is
an important part of maintaining and administering business-critical
systems and networks.
- Services - used to monitor services and devices on
Windows NT, Windows 2000, and Windows XP computers.
- Processes - monitor individual processes with the Process
Monitor which is multi-functional; it can let you know when
a process has exceeded the threshold of CPU usage you specify,
and it can track when processes are instantiated or terminated.
- Cluster Servers - provides extensive and configurable
monitoring of Windows NT and Windows 2000 clusters by using
all seven sets of Cluster APIs:
- Cluster Management
- Cluster Database Management
- Group Management
- Network Interface Management
- Network Management
- Node Management
- Resource Management
- ASCII Files
- Exchange Server - enables you to perform end-to-end
monitoring of Microsoft Exchange 5.5 and/or Exchange 2000
- SQL Server - periodically execute SQL queries against
a database and generate a variety of notification options if
the results returned are different from what is expected
- Simple Network Management Protocol (SNMP) Object IDs
- enables you to query an SNMP Object ID (OID) and trigger notification
if the value is greater than, less than or equal to a specified
value
- Windows Management Instrumentation (WMI) - periodically
query the WMI database and generate alerts when the results
of the query change.
TCP/IP MONITORING:
- HTTP/HTTPS - in addition to checking availability,
you can also monitor your Web server's quality of service performance
by monitoring how quickly a response is returned
- SMTP - used to keep tabs on SMTP hosts, gateways and
services
- FTP - used to monitor the status and availability of
an FTP site
- POP3 - used to periodically check a POP3 mailbox for
availability
- Ping - used to send period ICMP echo requests to the
Agent (s) being monitored
- TCP Ports - in addition to checking port availability,
you can monitor quality of service by specifying a port's expected
response time
RECEIVERS:
- SNMP Traps - SNMP traps are treated as events; they
will appear in event views, they will be stored in the database,
and you can create Rules that trigger notification when any
SNMP trap is received.
- Syslog Messages - ELM supports the exchange of events
with Unix and Linux Syslog clients and servers. It can act as
both a Syslog client and a Syslog server, receiving both TCP
and UDP Syslog messages. Many network devices include Syslog
facilities enabling them to act as Syslog clients. By sending
and receiving Syslog messages, ELM can provide integrated cross-platform
support.
TYPES OF NOTIFICATIONS
- Alerts - convenient way to be notified of a critical
event, security breach, or performance problem
- SMTP Email - supports the sending of email notifications
- MAPI Email - enables you to send email notifications
through a MAPI-compliant email server such as Microsoft Exchange
or Lotus Notes
- Pagers - supports notification via many popular pager
services
- Short Message Service - supports the sending of email
notifications via SMS (the transmission of short text (160 characters
or less) messages to and from a mobile phone, fax machine and/or
IP address)
- Command Script - supports both the Windows Script Host
(WSH) as well as generic command line (cmd.exe) files
- Web Post - supports the posting of a form to an internal
or external Web site as a notification method, which is especially
useful in intranets, as well as for alphanumeric pagers
- Electronic Marquees - send event and alert information
to a supported electronic marquee via TCP/IP or via a serial
connection
- Text-to-Speech - includes support for the Microsoft
Speech API (SAPI) 5.0, and has speech integration built into
the ELM Server. Using this notification method, you can configure
the ELM Server to say an event, part of an event, or a custom
message when an alert or event occurs.
- SNMP Traps - any event received by the ELM Server can
be repackaged and transmitted as an SNMP trap to any SNMP management
systems in your organization
- Syslog - supports native, integrated Syslog messages
as a notification method
- Network Messages - supports the use of network pop-up
messages (aka "Net Send")
- Forward to ELM Server - can forward any Alert, Event,
Syslog message or SNMP trap to another ELM Server
- Beeps - configure the ELM Server to play a customizable
"beep" sound
- Sound Files - supports the playing of sound files in
WAV format
ARCHIVAL AND REPORTING:
- Database platforms - supports multiple database platforms
for archiving and reporting, containing alerts, events, knowledge
base articles and performance data. Choose from Microsoft Access,
Microsoft SQL Server (6.5 or later), Microsoft Data Engine (MSDE)
and Oracle. Want to use Microsoft Access? You won't need to
install Access on your ELM Server because ELM includes a licensed
runtime version of Microsoft Access that automatically creates
an Access database for use with ELM.
- Scheduled Reports - a built-in scheduler feature is
included that enables administrators to run reports at periodic
intervals. Reports can be produced on a scheduled basis in a
variety of formats (e.g., HTML, Rich-Text Format, ASCII), or
sent to a printer.
- Knowledge Base - includes a built-in database repository
for custom Knowledge Base Articles that are linked to event
data. Knowledge Base Articles can be used to annotate collected
events with customizable notes and comments.
USER INTERFACE:
- MMC User Interface - uses the Microsoft Management
Console (MMC) framework to host its primary user interface
- Customizable Views - you can customize any of the pre-populated
views, or create your own custom views to suit your specific
needs
- Wizard-based configuration - when adding Agents, creating
views, adding a new monitor item, or doing just about anything
else, you are guided through the process with intuitive and
easy-to-use Wizards
- XML Web Viewer - enables you to view data stored in
the ELM Server and can be accessed using any Web browser that
supports XML and Javascript. The XML Web Viewer provides administrators
with a variety of functions:
- View Events, Alerts, Knowledge Base Articles, Notification
Methods, Rules, Reports, etc.
- View item Properties
- Search Events (ELM Enterprise Manager and ELM Log Manager
only)
- Enable/Disable items
- Stop/Start Services
- Kill Processes
GENERAL:
- Item-level Security - integrates with and leverages
the Windows security subsystem, enabling administrators to secure
both containers and items
- Network Security - ELM can provide a whole host of
security solutions for your organization. ELM can help you monitor
your network's security perimeters, keeping a close watch on
your sensitive file servers, and help you to maintain your security
boundaries. ELM is firewall friendly, and transmits its data
from an Agent to the Server in encrypted form
- Data Encryption - includes a proprietary encryption
mechanism that can encrypt the data traveling between some of
its components
- .NET - .NET is Microsoft's platform for a set of XML
Web services that represent the next generation of software
from Microsoft. The goal of .NET is to connect our world of
information, devices and people in a unified, personalized way.
The foundation of .NET is based on the Windows Server family
of products and the suite of .NET Enterprise Servers.
You probably already have portions of .NET deployed in your
environment. Windows 2000 Server and the .NET Enterprise Servers
are already part of Microsoft's .NET platform. These applications
provide a highly-reliable foundation for enterprise infrastructure
and applications.
Using ELM Enterprise Manager, you can monitor all of Microsoft's
.NET Enterprise Servers such as Application Center, BizTalk
Server, Commerce Server, Content Management Server, Exchange
Server, Host Integration Server, Internet Security and Acceleration
Server, Mobile Information Server, SharePoint Portal Server
and SQL Server.
More Information
|