McAfee M4050 Troubleshooting Guide - Page 88

Using the InfoCollector tool, Introduction

Page 88 highlights

CHAPTER 8 Using the InfoCollector tool This section describes the following aspects of using the Infocollector tool:  Introduction (on page 79)  Running the InfoCollector (on page 80)  Using InfoCollector (on page 80) Introduction InfoCollector is an information collection tool, bundled with Manager that allows you to easily provide McAfee with McAfee® Network Security Platform-related log information. McAfee can use this information to investigate and diagnose issues you may be experiencing with the Manager. InfoCollector can collect information from the following sources within McAfee Network Security Platform: Information Type Description Ems.log Files Configurable logs containing information from various components of the Manager. The current ems.log file is renamed when its size reaches 1MB, using the current timestamp. Another ems.log is created to collect the latest log information. Configuration backup A collection of database information containing all Network Security Platform configuration information. Configuration files XML and property files within the Network Security Platform config directory. Fault log A table in the Network Security Platform database that contains generated fault log messages. Sensor Trace A file containing various McAfee® Network Security Sensor (Sensor)related log files. Compiled Signature A file containing signature information and policy configuration for a given Sensor. InfoCollector is a tool that can be used both by you and by McAfee. McAfee systems engineers can use the InfoCollector tool to provide you with a definition (.def) file via email. This file is configured by McAfee to automatically choose information that McAfee needs from your installation of Network Security Platform. You simply open the definition file within the InfoCollector and it will automatically select the information that McAfee needs from your installation of the Manager. Alternatively, a manual approach can also be used with InfoCollector, and you can select information yourself to provide to McAfee. For example, McAfee may ask you to select 79

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95

79
C
HAPTER
8
Using the InfoCollector tool
This section describes the following aspects of using the Infocollector tool:
Introduction (on page
79
)
Running the InfoCollector (on page
80
)
Using InfoCollector (on page
80
)
Introduction
InfoCollector is an information collection tool, bundled with Manager that allows you to
easily provide McAfee with McAfee
®
Network Security Platform-related log information.
McAfee can use this information to investigate and diagnose issues you may be
experiencing with the Manager.
InfoCollector can collect information from the following sources within McAfee Network
Security Platform:
Information Type
Description
Ems.log Files
Configurable logs containing information from various components of
the Manager. The current ems.log file is renamed when its size reaches
1MB, using the current timestamp. Another ems.log is created to collect
the latest log information.
Configuration
backup
A collection of database information containing all Network Security
Platform configuration information.
Configuration files
XML and property files within the Network Security Platform config
directory.
Fault log
A table in the Network Security Platform database that contains
generated fault log messages.
Sensor Trace
A file containing various McAfee
®
Network Security Sensor (Sensor)-
related log files.
Compiled
Signature
A file containing signature information and policy configuration for a
given Sensor.
InfoCollector is a tool that can be used both by you and by McAfee.
McAfee systems engineers can use the InfoCollector tool to provide you with a definition
(.def)
file via email. This file is configured by McAfee to automatically choose information
that McAfee needs from your installation of Network Security Platform. You simply open
the definition file within the InfoCollector and it will automatically select the information that
McAfee needs from your installation of the Manager.
Alternatively, a manual approach can also be used with InfoCollector, and you can select
information yourself to provide to McAfee. For example, McAfee may ask you to select