The Event Management tab displays the Intel vPro Event Log for the computer being managed. The events are displayed in the Intel vPro Event Log pane with information about severity, time, and entity together with a description. Selecting an event in the pane will display further details about the event in the area below the pane.
In the bottom right corner of the vPro Console window you see a security indicator, a lock icon. A closed lock indicates that a secured connection is being used, while an open lock indicates that an unsecured connection is being used. In the top right corner you see a network activity indicator that looks like a flower. This icon indicates that the vPro Console is waiting for response from the remote AMT device.
At the top of the vPro Console window you find a toolbar with tools that you can apply to the log. In addition to the Refresh button, the Remove All button, and the Save to File button (save events to a .txt (tab delimited) file or a .csv (comma delimited) file), a Filters and Subscriptions button is available.
Manage filters, alerts, and subscriptions
The Filters and Subscriptions button opens a window from which you can manage event filters, alerts and subscriptions.
The Event Filters, Alerts and Subscriptions window is divided into two areas, on the left a tree pane listing the alerts and filters set on the AMT device and on the right a dialog panel. The dialog panel changes depending on the node selected in the tree pane.
The toolbar above the tree pane contains buttons that you can apply to the tree nodes. The toolbar changes depending on the node you select in the tree pane.
Root node
If you select the root node, the dialog panel displays system information on two tabs:
• | Use the System Sensors tab to see a list of sensors and a detailed description of the currently selected sensor. |
• | Use the Alert Settings tab to change the SNMP community strings for alerts. |
In addition to the Refresh button on the toolbar, you see an Add Alert button, which you can use to add a new alert to the tree.
Note
The alert ID entry in the tree can be edited. However, depending on your user rights you may or may not be able to change alert ID entries and associated filters and subscriptions. Non-administrator users cannot change subscriptions owned by other users. Administrators can take ownership of other user's subscriptions (AMT 2.5 and later).
Alert id node
If you select an Alert ID node, the dialog panel displays a list of subscriptions for the alert. When an alert with the specified ID is triggered on the remote AMT device, the PET (Platform Event Trap) or SOAP (Simple Object Access Protocol) event will be sent to all IP addresses or URLs subscribing to this alert.
Note
A platform event is defined as an event that is originated directly from platform firmware (BIOS) or platform hardware independently of the state of the operating system or system management hardware. The Platform Event Trap format is used for sending a platform event in an SNMP Trap.
You can select and remove one or more subscriptions (click the first, hold down SHIFT, and click the next) from the list using the Remove button below the list.
You can also add SNMP subscriptions from the Add SNMP subscription section at the bottom of the Alert Subscriptions dialog panel:
1. | Enter the IP address you want to subscribe to the alert in the IP address field. |
2. | Select the Use custom community string check box (available on AMT 2.5 and later, disabled for older versions). |
3. | When you have selected the Use custom community string check box, the Community string field below will display public by default, but you can change it. |
4. | Then click the Add button to add the specified IP address to the list of subscriptions. |
In addition to the Refresh button on the toolbar, an Add Filter button is available. Use this button to create a new filter with default properties under the currently selected alert ID. The filter properties are displayed in the Event Filter Properties dialog panel on the right. Click the Apply button at the bottom of the dialog panel for the new filter with default properties to be created.
On the toolbar you will also see a Remove button. Use this to remove all filters under the selected alert node and cancel all the subscriptions. You will be prompted for confirmation when you select the Remove button.
Filter node
If you select a filter node, the dialog panel displays editable properties for the selected filter:
Property section
|
Description
|
Filter settings
|
In the Filter settings section you can enable the filter by selecting the Enable event filter check box. If you do not select the check box, the filter is disabled and no actions are performed.
|
Filter criteria
|
In the Filter criteria section you can set various criteria for the filter. When an event matches the specified filter criteria, the action specified in the Filter action section will be performed.
|
Filter action
|
In the Filter action section you can set the action to be performed when the event matches the specified filter criteria.
Selecting the Log event check box will have the effect that events matching the specified filter criteria will be written to the log on the AMT device.
Selecting the Alert event check box will have the effect that events matching the specified filter criteria will trigger the alert.
|
Alert settings
|
In the Alert with severity field you can set the Event severity field in a PET alert. When an alert is generated either the event’s own severity or a severity for matching filters, whichever has the highest numerical value, will be used for the specified Alert ID.
Numerical values for severity levels:
00h
|
Unspecified
|
01h
|
Monitor
|
02h
|
Information
|
04h
|
OK (return to OK condition)
|
08h
|
Non-critical, a.k.a Warning
|
10h
|
Critical
|
20h
|
Non-recoverable
|
Example:
We have an event with the severity Monitor and 3 filters match the event. Alert with severity for one filter is set to Unspecified, for the second filter to Information and for the third filter to Critical. The value Critical will then be used. This is because the severities correspond to numerical values: Unspecified corresponds to the lowest value, Monitor corresponds to a higher value, Information corresponds to an even higher value, and Critical corresponds to the highest value of the four.
If all filters have the severity Unspecified, then the event's original Monitor severity will be used because it constitutes the severity with the highest numerical value.
In the Alert ID list, select the filter's Alert ID.
|
You must click the Apply button to save any changes that you make to the filter properties. If you click Close after having made changes to the properties, you will be asked whether you want to save the changes.
|