ecsd

- HP OpenView Event Correlation Services Standalone Engine

SYNOPSIS

For UNIX:
ecsd [-e filepath] [-F] [-i instance] [-L mask] [-m filepath] [-T mask] [-C mask] [option...] [-? |-h]
For Windows NT
ecsd [-install |-remove | -console] [-e filepath] [-F] [-i instance] [-L mask] [-m filepath] [-T mask] [-C mask] [option...] [-? |-h]

DESCRIPTION

ecsd is the HP OpenView Event Correlation Services (ECS) standalone correlation engine. ecsd uses the Event IO (EIO) API to receive events from and forward events to user applications.

The default behavior of ecsd is to run as a daemon.

ecsd is controlled with the ecsmgrcommand.

The configuration of ecsd including streams, circuits, data/factstores and their relevant state is automatically restored from the default startup configuration file (Unix: $OV_CONF/ecs/instance/config, Windows NT: %OV_CONF%\ecs\instance\config). If the file is not present, ecsd starts up in a reset state. See -restore_config for details.

The default policy of the correlation engine is to output events not selected for input by any of the enabled (running) correlation circuits. This policy can be controlled with the ecsmgr -policy command.

OPTIONS

The following options can be used to influence the behavior ofecsd:

-install
Used for Windows NT only. It installs ecsd as a Windows NT service. The ecsd service must be installed before it can be started. To install an ecsd service, use the following command:

ecsd.exe -install

Any additional options will be ignored.

-remove
Used for Windows NT only. It removes the ecsd service from a Windows NT system. To remove an ecsd service, use the following command:

ecsd.exe -remove

Any additional options will be ignored.

-console
Used for Windows NT only. It specifies that ecsd should run as a foreground console application. To run ecsd as a background process, start it using the Services option in the Windows NT Control Panel. Note that the ecsd service must be installed using the -install option before you can start it. For information on installing the ecsd service, see the -install option above.
-e path/ed.conf
Specifies an alternate ed.conf file.
-F
Forces ecsd to run in the foreground, rather than as a daemon process.
-I instance
Specifies the correlation engine instance. The instance uniquely identifies a correlation engine instance running on a machine. If this option is not specified, a default engine instance of 1 is used. If a duplicate correlation engine instance is specified, undefined behavior will result.
-L mask
Sets the level of log information generated by the correlation engine. The level is specified as a 32-bit mask. This option is equivalent to setting the log mask with the ecsmgr -log option. See the ecsmgr reference page for further details. If this option is not specified, an engine log mask of 0x7 is used.
-m path/MDL_metadata
Specifies an alternate MDL metadata file.
-reset
Starts up the engine in a reset state, effectively ignoring the contents of the default startup configuration file (Unix: $OV_CONF/ecs/instance/config, Windows NT: %OV_CONF%\ecs\instance\config).
-restore_config [configfile]
Overrides the configuration file that the engine is restored from. The configuration is read from configfile if specified or from the default startup configuration file (Unix: $OV_CONF/ecs/instance/config, Windows NT: %OV_CONF%\ecs\instance\config) otherwise.

This command assumes that circuits and data/factstores will be found in the same place as when the configuration was saved. If an error occurs during restoration, the engine will keep going to restore as much as possible.

-T mask
Sets the level of trace information generated by the correlation engine. The level is specified as a 32-bit mask. This option is equivalent to setting the trace mask with the ecsmgr(1m) -trace option. If this option is not specified, an engine trace mask of 0 is used.
-C mask
This sets the components of the correlation engine that will report tracing when it is enabled with the -T option. The set of components is specified as a 32-bit mask. If this option is not specified, all components will be traced.
-? | -h
Displays the ecsd usage message.

RETURN VALUES

ecsd returns 0 upon normal completion and >0 if an error occurred.

EXAMPLE

To start a standalone correlation engine as a daemon process:

ecsd

To start a standalone correlation engine in the foreground:

ecsd -F

To set the default logging level to DISASTER and ERROR messages only:

ecsd -L 0x3

DIAGNOSTICS

ecsd outputs diagnostic messages to its error log. If the error logging subsystem cannot be initialized, then ecsd will report a message to the standard error output. If ecsd has been started as a daemon, stderr output may appear in the ecsd.stderr file specified below.

FILES

The environment variables below represent universal pathnames that are established according to your shell and platform requirements. See the ovenvvars(1) reference page for information on universal pathnames for your platform and shell. For Windows NT platforms, substitute the environment variables in Windows NT format. For example, substitute $OV_LOG with %OV_LOG%.

$OV_LOG/ecs/instance/ecsd.log*
Engine log output file for standalone engine instance instance.
$OV_LOG/ecs/instance/ecsd.trc*
Engine trace output file for standalone engine instance instance.
$OV_LOG/ecs/instance/ecsd.stderr
Standard Error output for the correlation engine with the corresponding instance number. This is only applicable if the correlation engine is running as a daemon.
$OV_LOG/ecs/instance/ecsin.evt*
Input event log file for engine instance instance.
$OV_LOG/ecs/instance/sname_sout.evt*
Output event log file for the stream sname in engine instance instance.
$OV_LOG/ecs/instance/sname_sdis.evt*
Discard event log file for the stream sname in engine instance instance.
$OV_LOG/ecs/instance/cname_cout.evt*
Output event log file for the circuit cname in engine instance instance.
$OV_LOG/ecs/instance/cname_cdis.evt*
Discard event log file for the circuit cname in engine instance instance.
$OV_LOG/ecs/instance/sname_pout.evt*
Output event log file for events not accepted by any circuit in the stream sname in engine instance instance.
$OV_LOG/ecs/instance/sname_pdis.evt*
Discard event log file for events not accepted by any circuit in the stream sname in engine instance instance.
$OV_CONF/ecs/instance/config
The default startup configuration file for engine instance instance that is restored by the engine on startup.
$OV_CONF/ecs/md/mdl/mdl.md
Default metadata file name for the MDL encoder/decoder.
$OV_CONF/ecs/md/ber/ecs.*
Default metadata files used by the BER encoder/decoder.
$OV_CONF/ecs/ed/ed.conf
Default endecoder configuration file for the correlation engine.

Valid encode/decode module abbreviations are:

MDL enables the ASCII/MDL encode/decode module.

SNMP enables the SNMP encode/decode module.

CMIP enables both the CMIP and SNMP encode/decode modules.

Use of these encode/decode modules requires that an appropriate license be available.

$OV_SOCKETS/ecs/instance/socket
The Unix domain socket used to communicate to a specific ecsd standalone correlation engine instance instance.

AUTHOR

ecsdwas developed by Hewlett-Packard.

SEE ALSO

ecsdes

ecsmgr

ecslogmsg(5)