This topic discusses the Raw Logs Search in detail. The Home Page is the page that is displayed immediately after a successful login.
Raw log files are files that are not indexed. They are displayed here in their original format as they come into the system. All data is stored in raw log file format. Data that is indexed is also stored in indexed or tabular form, but the raw log file format remains.
The Main Log area
By default when you login for the first time the details under the Logs are displayed as shown below. By default 10 entries are displayed per page but this can be changed.
Additional pages of information can be accessed via the page numbers below the screen.
Another option would be to select more number of detail lines per page and this can be done by clicking an option from the No.of lines per page filter as shown below.
In the above case, the page would instantly refresh to display 50 lines of details per page as shown in the image below.
Basically what this page displays is the details of the raw log files and also provides means to search this data.
The Instant Graph
This graph shows the raw file log size in that time range across various servers. It has several other functionality too. For more details click the Instant Graph topic.
Accessing the modules and menus
You can access the various modules by clicking the Logs, Indexing and Reporting links. Further options for filtering and categorization are provided once a particular function is accessed.
To access menus as in the case of the Alerting and Configuration menus, click the tile and a drop-down appears.
We have already seen the Username menu in the How to Login to OTUS SIEM Online topic.
Latest notifications button
This button is located very near the Username menu. Clicking on it displays the most recent notifications in a pop-pup a shown below.
You can click a notification to reveal more details of the notification in a table-view format. You can also click Show All inside the pop-up to view all the notifications in the main log area or table-view format.
Note: Please view the topic Notifications in detail for more information on notifications.
Filtering the Data
You can also filter the data of the logs displayed on the Main Log Area by clicking one or more of the filters. Please view the Filtering Data using filters topic for details.
Create Alert Query button
Clicking this button leads to creating raw alert query based on search parameters.