The log files processed by the EventLog Analyzer are archived periodically for internal, forensic, and compliance audits. The archival interval and retention period is configurable. The archive file can be encrypted and time-stamped to make it secure and tamper-proof.
Archived Files page lists all the archived files in a table with the hosts for which the files were archived, start time of archiving, the time at which archived, size of the archived file, the status of the file and action on the file. If the number of archived files is more and if manual viewing and selection is not possible, use the search archived files (search icon) to filter the required files in the list.
How to delete archived files?
1a. Select the archived file(s) by selecting the respective check box(es)
1b. Delete the archived file(s) using the Delete link.
How to generate report from the archived files?
Check the status of the archived file. If it is ‘Not Loaded’, click the ‘Load & Search’ action to load the file in to the database and search the logs.
If the status of the file is ‘Loaded’, click the ‘Search’ link to search the logs in the file. If you want to drop the file from the database, click the ‘Drop DB’ link.
Configure the archival interval, retention period, option to encrypt, time-stamp the archive files, location to save the archive files and location to save the index files in this screen.
Ensure that the archiving is enabled. By default it is enabled. Unselect the check box to disable archiving
The logs are written in to flat files at the specified time period. Choose the required time interval. The default value is 12 Hours
The flat files are compressed (20:1 ratio) and zip files are created at the specified time period. Choose the required time interval. The default value is 4 days
To secure the archive files, enable encryption of the files. By default, it will be in disabled state
To make the archive files tamper-proof, enable time-stamping of the files. By default, it will be in disabled state
Select the log retention period. The default value is ‘Forever’
The default archive storage location is displayed and to change the location as required, use the Edit link
The default indexed data storage location is displayed and to change the location as required, use the Edit link
Save the settings and close the window. For instant archiving, use the ‘Zip now’ button.