Indexing log search

Navigation:  »No topics above this level«

Indexing log search

Previous pageReturn to chapter overviewNext page

OTUS SIEM offers fast and simple access to relevant data. Indexing is the process where the raw log data is analyzed by an indexer and the important components are extracted and stored in a table form providing for better and concentrated searches to be performed. This yields more meaningful results. About 70+ integrated indexers are available in OTUS SIEM from various software and hardware vendors.

 

Clicking Indexing from the Indexing (menu) displays the tabs for the various indexers in use currently. You can then load indexed data from a particular indexer by clicking on one of these tabs. The main log area displays the logs related to that particular tab/indexer selected. In the following image the mail-postfix indexer has been selected by default and its details reported.

 

Note:   The names of indexers (mail-postfix), etc are not constant, they depend on which indexers you use in the Distribution (PULL,SYSLOG,SNMP) indexer column. All currently used indexers are defined here.

 

indexing_logs

 

As in the case of Indexing if there are more columns that can fit the page, you can use the horizontal scroll-bar at the bottom of the page to scroll left and right to view the hidden columns as can be seen in the image above.

 

Note:   When you click on an indexed row one or more raw log lines from which indexed row was constructed is displayed as shown below.

 

indexed_record_clicked

 

 

For creating an indexed alert query based on search parameters click creat_alertquery_btn. For more information refer the Create and Managing Alert Queries topic.

 

To use the filters and conditions refer the topic Filtering data using filters.

 

To use the graph refer the topic Instant Graph.