- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Data Flow in enVision
Hi,
I am a bit confused about the data flow in enVision say from a Network Device to my Local Collector to the IPDB and to the Coorelation Engine and then finally to the GUI as an alert.
How does this flow takes place. What are the various stages in which data flows?
Thanks
MJ
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
At a very high level, the events are collected, processed simultaneously for alerting and into the IPDB, and then can be retrieved for reporting through the GUI.
There is a more precise diagram of the enVision data flow in the Help file. If you access enVision Help, then do a seach for "data flow" (include the double quotes), it will be the first topic that comes up.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Thanks for the info Matt.
However, I am not able to understand the concept of "processed simultaneously for alerting and into the IPDB".
In the attached diagram, the event messages first goes to the logsmart(I believe this is the IPDB) and then from there the event files are retrieved by the Alerter service, which takes "View Configuration Data" from the config data, and sends the ALert data back to the IPDB.
Can you further explain me whyyou say that "At a very high level, the events are collected, processed simultaneously for alerting and into the IPDB, and then can be retrieved for reporting through the GUI."
Appreciate your prompt response.
Thanks
MJ
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
What I mean is that as soon as an event enters the IPDB, the Alerter service takes note of it. If it meets the criteria to trigger an alarm it writes an Alert Event back into the IPDB and sends out a notification using whichever other methodologies you have configured (console, e-mail, SNMP, etc).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hi Matt,
Thanks for the info. Can you tell me the exact location of the Directory on NAS where Alerts are stored.
Is it on Vol0 or Vol1?
Thanks
MJ
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
It depends on the nature of the setup and where the alert came from.
If the alert was generated from an event on LC1 - it ends up on vol1
If the alert was generated from an event on LC2 - it ends up on vol2
If the alert was generated from an event on LC3 - it ends up on vol3
If the alert was generated from an RC or the enVision software itself, it ends up on vol0
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
But all I can see on the NAS Vol1 is a "Data" folder and then the subsequent folders starting with device type, indivisual device IP, year and month fodler and the day folder where the files are stored. I believ this is what is called the IPDB and this is the location where all the incoming data is stored.
But I do not see the alerts stored here or on the Vol0.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
OK. So are you saying that when I use the "lsmaint" command with the 'move' parameter, the alert events are also backed up along with the event data?
The packager service is responsible for storing the event data onto the NAS. Is it also responsible for storing the alert events.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Yes - that is correct.
