User guide

34
<!-- When the below option is set to yes, only syslog messages are reported, and
all
all other traffic is ignored. -->
<syslog-only>no</syslog-only>
<!-- The following section defines the networks on which syslog will be monitored.
The network monitor will report syslog messages received at the above
specified
ports for any IP address matching the filter criteria. -->
<include-networks>
<filter>192.168.20.5/32</filter>
<filter>127.0.0.1</filter>
</include-networks>
<exclude-networks>
</exclude-networks>
<!-- The heartbeat-frequency option defines the number of seconds between each
pair
of client heartbeat messages that are sent to the server. -->
<heartbeat-frequency>300</heartbeat-frequency>
<!-- The LCE client provides the option of periodically sending a log file
containing
performance statistics to the LCE server. The following option determines the
number of minutes between each performance statistics report. When the next
line
is commented out or removed, performance reporting is disabled. -->
<statistics-frequency>60</statistics-frequency>
<!-- LCE clients can compress log data prior to sending it to the LCE server,
saving bandwidth.
For debugging purposes, event packet compression may be disabled, but this
will
increase the bandwidth required to send data from LCE clients to the LCE
server.
Setting the following option to 0 will disable compression only during
transmission. -->
<compress-events>1</compress-events>
</options>
Option
Description
log-directory
Directory where LCE Client logs are stored. If the log-directory keyword is
commented out, then the client install directory will be used. Otherwise, ISO 9000
compliant log files will be saved in the specified directory.
heartbeat-frequency
The Tenable Network Monitor can be configured to send a "heartbeat" message to the
LCE. This message indicates that the client is still alive and performing normally.
statistics-frequency
The frequency with which the Tenable Network Monitor sends a log entry containing
performance statistics to the LCE.
filter-expression
The network monitor automatically generates a TCPDUMP filter expression that