Raw Logs Search in detail

Navigation:  The Raw Logs Search >

Raw Logs Search in detail

Previous pageReturn to chapter overviewNext page

This topic discusses the Raw Logs Search in detail. The Home Page is the page that is displayed immediately after a successful login.

 

Raw log files are files that are not indexed. They are displayed here in their original format as they come into the system. All data is stored in raw log file format. Data that is indexed is also stored in indexed or tabular form, but the raw log file format remains.

 

otus_home_page75p

 

The Main Log area

 

By default when you login for the first time the details under the Logs are displayed as shown below. By default 10 entries are displayed per page but this can be changed.

 

logs_function

 

Additional pages of information can be accessed via the page numbers below the screen.

 

first_last_pages

 

Another option would be to select more number of detail lines per page and this can be done by clicking an option from the No.of lines per page filter as shown below.

 

10_pages

 

selecting_lines_perpage

 

In the above case, the page would instantly refresh to display 50 lines of details per page as shown in the image below.

 

50lines_perpage

 

Basically what this page displays is the details of the raw log files and also provides means to search this data.

 

 

The Instant Graph

This graph shows the raw file log size in that time range across various servers. It has several other functionality too. For more details click the Instant Graph topic.

 

 

Accessing the modules and menus

 

You can access the various modules by clicking the Logs, Indexing and Reporting links. Further options for filtering and categorization are provided once a particular function is accessed.

 

To access menus as in the case of the Alerting and Configuration menus, click the tile and a drop-down appears.

 

alerting_menu

 

configuration_menu

 

We have already seen the Username menu in the How to Login to OTUS SIEM Online topic.

 

 

Latest notifications button

 

This button is located very near the Username menu. Clicking on it displays the most recent notifications in a pop-pup a shown below.

 

latest_notifications

 

You can click a notification to reveal more details of the notification in a table-view format. You can also click Show All inside the pop-up to view all the notifications in the main log area or table-view format.

 

Note:   Please view the topic Notifications in detail for more information on notifications.

 

Filtering the Data

 

You can also filter the data of the logs displayed on the Main Log Area by clicking one or more of the filters. Please view the Filtering Data using filters topic for details.

 

 

Create Alert Query button

 

creat_alertquery_btn

 

Clicking this button leads to creating raw alert query based on search parameters.