Using Advanced Search


 

EventLog Analyzer provides advanced search feature. Advanced Search, offers numerous options for making your searches more precise and getting more useful results. It allows you to search from the Raw Logs. Using this feature, you will be able to save the search results as Report Profiles. This provides a simplified means to create very precise, selectively filtered and narrowed down Report Profiles.

Advanced Search

In Advance Search, you can search the logs for the selected hosts, from the aggregated logs database or raw Host/Application logs, and define matching criteria.

 

  1. To carry out advanced search, click Advanced Search link in the Sub Tab. Advanced Search screen opens up and there will be Search Criteria section. Search Criteria has two sub-sections.

Select Hosts

 

In this sub-section, you can choose the hosts for which you want the logs to be searched. If no host is selected or you want to change the list of selected hosts, select the hosts.

  1. Click Click to Select link.
  2. Select Hosts window pops-up. In that window, Select All Groups with selection check box and all the available host groups with individual hosts with selection check boxes are listed. By default, the Default Group and the hosts with selection check boxes are displayed in the screen
  3. Select the host groups or individual hosts in the groups by selecting the check boxes as per your requirement. Click Done to select the hosts and close the window or click Cancel to cancel the operation and close the window.

The selected groups and hosts are displayed in this section.

Select Criteria

 

In this sub-section, you can define the criteria listed below to search the event database for incidents:

 

Criteria Description
Type Refers to major and particular event types. Major event types are: EventLog Types, Syslog Types
Severity Refers to the following event severity listed: Emergency, Alert, Critical, Error, Warning, Information, Notice, Debug, Success, Failure
User Name Refers to the User Name of the user associated with the log events
Event ID Refers to the Event ID of the log events
Source

Refers to the source host name or IP address from which the events originated

Message Refers to the log message texts stored in the database

 

Type Sub-Criteria

 

If no event type is selected or you want to change the selected event types, select the event types.

  1. Click Click to Select link.
  2. Select Event Types window pops-up. In that window, EventLog Types and Syslog Types and individual event types are listed with selection check boxes. Selecting EventLog Types check box will select all the event types listed under EventLog Types. Same is applied for Syslog Types.
  3. Select the complete lists or individual event types in the lists by selecting the check boxes as per your requirement. Click Done to select the event types and close the window or click Cancel to cancel the operation and close the window.

The list of event types under Eventlog Types are:

  1. Application
  2. Security
  3. System
  4. DNS Server
  5. File Replication Service
  6. Directory Service
  7. OSession

The list of event types under Syslog Types are:

  1. kernel
  2. user
  3. mail
  4. daemon
  5. auth
  6. syslog
  7. lpr
  8. news
  9. uucp
  10. cron1
  11. authpriv
  12. ftp
  13. ntp
  14. logAudit
  15. logAlert
  16. cron2
  17. local0
  18. local1
  19. local2
  20. local3
  21. local4
  22. local5
  23. local6
  24. local7
  1. Select any combination of the following criteria: Type, Severity, User Name, Event ID, Source, and Message.
  2. After selecting the Host(s) and Criteria, click Search or click Cancel to cancel the operation.
  3. Clicking Search will display the results in the Search Results section below the Search Criteria section.

The Search Results screen displays the following:

Note

If the search string exists then the search result will be intelligently displayed based on the report category in which it occurred.

 

 

Using Advanced Search to create Report Profile

To generate users reports:

 

Copyright © 2012, ZOHO Corp. All Rights Reserved.
ManageEngine