2014-02-28 01:57 PM
When using envision I could go into the events and do a flat search across anything. So I could select Linux and search for user1 and any message that had user1 would come back. Is there anyway to do this in SA? To this day I still have not found the way.
2014-02-28 03:07 PM
you're talking about event viewer aren't you - so a raw event search?
You are right - no such thing exists. A fundamental part of any SIEM solution but not currently available in SA as yet. Let's hope it's in 10.4.
2014-02-28 03:07 PM
you're talking about event viewer aren't you - so a raw event search?
You are right - no such thing exists. A fundamental part of any SIEM solution but not currently available in SA as yet. Let's hope it's in 10.4.
2014-03-03 08:13 AM
This kind of query is possible using Investigator 9.8, which works with any version of 9.x or 10.x. You can drill in on your events and type in a text or regex search in the upper right search field of the breadcrumb bar.
2014-03-03 08:22 AM
In SA 10.3.2, you still need a metakey to search off of. I have found a kinda work around but it is really bad to use I think in the long run for data retention by adding "msg" as an indexed field.
2014-03-28 02:40 PM
Sean,
How has this worked for you? We are thinking to turn this on for our syslog event sources because our users need raw searching and in 10.3 you can then go into Events tab and search through raw logs of any device type using: msg contains 'blah'. Has this affected your retention much? I'd suspect it would only decrease retention by 50% which we can afford but I'm more curious as to the system impact you've seen from the Concentrator getting busier to index a large field like a syslog message.
I'd love to hear about your experience.