Device Management
All the devices added to EventLog Analyzer for monitoring can be viewed under Settings > Configuration > Manage Devices.
In this page, you can find three tabs: Windows Devices, Syslog Devices and Other Devices. Under Windows Devices, you can use the Select Category drop-down menu to select a domain or workgroup.
- Devices are displayed with the following icons: Search, Enable, Disable, Filter Change Monitor time interval, and Delete. The Filter option lets you choose the devices for reports by their status (enabled/disabled), state (active/inactive) and device group.
- The table displays the following columns:

- Checkbox against all devices
- Actions: Configure event source file and Update icons.
- Device Name
- Device IP address
- Last Message Time
- Last Event Collected On
- Next Scan On: Shows when the next scan is scheduled. The Scan Now link against each device will scan the device instantly.
- Monitoring Interval: The period for collection of logs.
- Device Group
- Status: Status of log collection.
Quick Links
Manage Devices
How to add a device?
Refer to Add Device.
How to delete a device?
- Go to Settings > Configuration > Manage Devices.
- Select the appropriate tab from Windows Devices, Syslog Devices, Other Devices.
- Select the checkbox(es) against the respective device(s).
- Click the delete icon in the action menu.
- Click Yes in the delete confirmation pop-up.

How to disable/enable a device?
- Navigate to Settings > Configuration > Manage Devices.
- Select the appropriate tab from Windows Devices, Syslog Devices, Other Devices.
- Select the device(s) by selecting the respective check box(es).
- Click the disable or enable icons in the action menu.
How to change the monitoring interval?
- Navigate to Settings > Configuration > Manage Devices > Windows Devices
- Select the device(s) by selecting the respective check box(es).
- Click the Change monitor interval icon in the action menu.
- In the box that opens, select the time interval in minutes as needed.
- Click Update.

Note: You can select multiple devices and configure them for either
- Real-time log collection (or) b) Scheduled collection with similar monitoring interval.
How to update a device's configuration?
- Go to Settings > Configuration > Manage Devices > Windows Devices.
- Click the edit icon for the device. For Syslog Devices and Other Devices,hover over the device for edit icon to appear.
- This opens the Update Device box where you can edit Device Type, Device IP Address, Display Name and Log Collection Mode.
Note: The Log Collection Mode can be configured either for real-time log collection or for scheduled collection with monitoring interval.
- Click Advanced to edit Encoding Type and Time zone.
- Click Update.

How to configure event source files in a device?
- Go to Settings > Configuration > Manage Devices > Windows.
- Click the Configure Event Source Files icon for the device.
- In the Event source files dialog box, select the type(s) of event source files.
- Click Configure.

Note: The registry is accessed for configuring event source files. Modifications to a registry entry will reflect only when reloaded. This feature supports Windows XP Pro and above.
Configure Auto Log Forward for Unix devices
- Go to Settings > Configuration > Manage Devices > Syslog Devices.
- Select the Unix device by ticking the checkbox.
- Click Configure Auto Log Forward in the Actions menu.
- Enter the root login credentials for the Unix device and SSH port number.
- For configuring syslog forwarding , enter the IP address of the EventLog Analyzer server.
- Select the protocol — TCP/UDP.
- Specify the Syslog Port number. Note that the default port numbers are 513 and 514 for UDP and 514 for TCP.
- Click Verify & Update.