Sys Maintenance: Event Source Monitoring View

Document created by RSA Information Design and Development on Nov 23, 2016Last modified by RSA Information Design and Development on Aug 2, 2017
Version 10Show Document
  • View in full screen mode
  

Note: This panel is being deprecated. To manage Event Sources, see About Event Source Management in the RSA Security Analytics Event Source Management Guide.

Security Analytics provides a way to monitor the stats for various event sources in the User Interface.The information displayed is historical and comes from the Log decoder. You can customize the view depending on the parameter you select to filter the data.

To access the Event Source Monitoring view:

  1. In the Security Analytics menu, select Administration > Health & Wellness.

    The Health & Wellness view is displayed with the Monitoring tab open.

  2. Click Event Source Monitoring.

    The Event Source Monitoring view is displayed.

event_source_monitoring_view.png

For related procedures, see Monitor Event Sources, , Filter Event Sources, and Create Historical Graph of Events Collected for an Event Source.

Filters

This table lists the various parameters you can use to filter and customize the event source monitoring view. 

                                   
ParameterDescription
Event SourceType the name of an event source you want to monitor.
Select Regex to enable Regex filter. It performs a regular expression search against text and lists out the specified category. If Regex is not selected it supports globbing pattern matching.
Event Source TypeSelect an event source type for the event source selected. 
Log CollectorSelect the Log Collector to display the data collected by the specified Log Collector.
Log DecoderSelect a Log Decoder to display the data collected by the specified Log Decoder.
Time FrameSelect the time frame for which you want the stats. 
Select Received if you need the query results to contain only event sources that logs have been received from within the selected time.
or
Select Not Received if you need the query results to contain only event sources that logs have not been received from within the selected time
Order BySelect the order in which the list needs to be filtered. 
Select Ascending to filter it in an ascending order.

Commands

                       
CommandAction
ApplyClick to apply the filters chosen and display the list accordingly.
ClearClick to clear the chosen filters.
Export as CSVClick to export the information as a csv file.

 

Event Source Stats view display

                                           
ParameterDescription
Event SourceDisplays the name of the event source.
Event Source TypeDisplays the event source type.
Log CollectorDisplays the Log Collector from where the events were initially captured.
Log DecoderDisplays the Log Decoder where the events are being processed.
CountDisplays the number of events received by Log Decoder since last reset of count value.
Idle TimeDisplays the time lapsed after the last stat collection.
Last Collected TimeDisplays the time at which the Log Decoder last processed an event for the event source
Historical GraphClick  rrd_graph_icon.png to view the historical graph of the stats collected for the event source. 
Previous Topic:Alarms View
You are here
Table of Contents > References > Health and Wellness > Event Source Monitoring View

Attachments

    Outcomes