Notifications in detail

Navigation:  The Raw Logs Search > Raw Logs Search in detail >

Notifications in detail

Previous pageReturn to chapter overviewNext page

There are three types of notifications. The table below summarizes their properties

 

Notification Type

Property

Examples

notification_green

General and Informational

successful PULL copy,

successful PUSH copy (syslog,snmp),

successfully detected  PULL copy time format,

new PUSH server autodetected, configuration pending, match on alert rule

notification_orange

Warnings

failed PUSH copy - no PULL copy method discovered

failed PULL copy - autodetect if server didn’t receive no PULL data for longer periods of time

 

push fail (  ), storage usage treshold (  ),  failed time format, invalid time format,

notifications_red

Errors

system alert ( internal OTUS exception) This exception can only be seen by the Superuser role.

 

Note:   Autodetect notifications are always on top of others until you confirm them or reject them. Once confirmed OTUS SIEM will try to get the server name from server address. If it fails it means there is no DNS entry and therefore a notification of the same. For example if there was a name such as srv1.dobarmail.com then it would mean that the DNS is configured properly and consequently you will not get notifications for that server again. Autodetect works for PUSH copy types (SYSLOG,SNMP)

 

You can auto-configure a server for incoming SYSLOG data as indicated by a notification shown below. Click Yes to auto-configure the server. This is an auto-detect feature used by OTUS to configure the remote server to send data that is not inside the OTUS configuration. This is the fastest way to auto-configure new servers.

 

latest_notifications_cnf

 

Note:   Please refer the Creating and Managing Servers topic  for more information on Auto-Configuration.

 

Clicking Show All opens the following page displaying all notifications of the system assigned to the logged in user's account.

 

notifications_all

 

Note:   The variables notification web notify alert, notification web notify job success, notification web notify push success and data retention

total usage warning limit under Configuration -> Settings are related to the functions of the notifications. Please refer the topic Managing Settings for more details.

 

 

To view Alert type of notifications

 

1.   Click the link for detailed information on that notification. In our example the link of the first alert is clicked. The following page is displayed.

 

alert_notification_detail

 

The graph suitably adjusts to display information related to that alert. Information of the same alert at various times and dates appear in the table below. From this page you could skip to other alerts too as can be seen in the various tabs below the selected tab for that particular alert you selected.

 

2.   Click an alert from this table displays more information as displayed below.

 

alert_notification_more_info

 

Note:   Depending on the type of notification OTUS responds with various screens. As mentioned earlier in the above example an alert was selected.

 

 

To view a Copy type of notification

 

1.   Click on a copy type of notification. The following page is displayed displaying more information.

 

copy_notification_detail

 

2.   Using the filters (explained in the topic Filtering data using filters) more specific data can be searched and fetched.

 

 

To view a system event

 

1.   Click the system event notification from the list of notifications. The following page is displayed.

 

system_event_notification

 

2.   Here too, using the filters (explained in the topic Filtering data using filters) more specific data can be searched and fetched.