This discussion has been locked. The information referenced herein may be inaccurate due to age, software updates, or external references.
You can no longer post new replies to this discussion. If you have a similar question you can start a new discussion in this forum.

What goes into the "Data" field when defining the "Approved DNS Servers?"

I'm discovering that many of the predefined groups don't contain any information. For example, I'm working through the best practices recommendations for the LEM product and discovered that the "Approved DNS Servers" user defined group doesn't contain a list of servers. So, what goes into the "data" field for this template? Is it the DNS server's IP address or FQDN?

~Steve

  • Hello again, Steve.

    Use the machine name of your servers, surrounded by asterisks. The asterisks serve as wildcard characters so you don't have to enter the FQDN.

    If you find that the alerts needed for your rules/filters/etc. reflect IP addresses instead of machine names, you might consider cloning the group and having one with machine names and one with IP addresses. This shouldn't be necessary, however, because the vast majority (maybe all) of the Windows messages you'll be using with this group log machine names, not IP addresses.

    Let me know if you run into any snags.

    Thanks.

  • For additional information about what groups need to be customized and how to customize them, check out this new KB: Getting Started with User-Defined Groups.

    Thanks for the tip! :)