There are three types of notifications. The table below summarizes their properties
Notification Type |
Property |
Examples |
|
General and Informational |
successful PULL copy, successful PUSH copy (syslog,snmp), successfully detected PULL copy time format, new PUSH server autodetected, configuration pending, match on alert rule |
|
Warnings |
failed PUSH copy - no PULL copy method discovered failed PULL copy - autodetect if server didn’t receive no PULL data for longer periods of time
push fail ( ), storage usage treshold ( ), failed time format, invalid time format, |
|
Errors |
system alert ( internal OTUS exception) This exception can only be seen by the Superuser role. |
Note: Autodetect notifications are always on top of others until you confirm them or reject them. Once confirmed OTUS SIEM will try to get the server name from server address. If it fails it means there is no DNS entry and therefore a notification of the same. For example if there was a name such as srv1.dobarmail.com then it would mean that the DNS is configured properly and consequently you will not get notifications for that server again. Autodetect works for PUSH copy types (SYSLOG,SNMP)
You can auto-configure a server for incoming SYSLOG data as indicated by a notification shown below. Click Yes to auto-configure the server. This is an auto-detect feature used by OTUS to configure the remote server to send data that is not inside the OTUS configuration. This is the fastest way to auto-configure new servers.
Note: Please refer the Creating and Managing Servers topic for more information on Auto-Configuration.
Clicking Show All opens the following page displaying all notifications of the system assigned to the logged in user's account.
Note: The variables notification web notify alert, notification web notify job success, notification web notify push success and data retention
total usage warning limit under Configuration -> Settings are related to the functions of the notifications. Please refer the topic Managing Settings for more details.
To view Alert type of notifications
1. Click the link for detailed information on that notification. In our example the link of the first alert is clicked. The following page is displayed.
The graph suitably adjusts to display information related to that alert. Information of the same alert at various times and dates appear in the table below. From this page you could skip to other alerts too as can be seen in the various tabs below the selected tab for that particular alert you selected.
2. Click an alert from this table displays more information as displayed below.
Note: Depending on the type of notification OTUS responds with various screens. As mentioned earlier in the above example an alert was selected.
To view a Copy type of notification
1. Click on a copy type of notification. The following page is displayed displaying more information.
2. Using the filters (explained in the topic Filtering data using filters) more specific data can be searched and fetched.
To view a system event
1. Click the system event notification from the list of notifications. The following page is displayed.
2. Here too, using the filters (explained in the topic Filtering data using filters) more specific data can be searched and fetched.