One Identity syslog-ng Store Box 5.3.0 User manual

syslog-ngStoreBox5.3.0
UserGuide

Copyright 2019 One Identity LLC.
ALL RIGHTS RESERVED.
Thisguidecontainsproprietaryinformationprotectedbycopyright.Thesoftwaredescribedinthisguide
isfurnishedunderasoftwarelicenseornondisclosureagreement.Thissoftwaremaybeusedorcopied
onlyinaccordancewiththetermsoftheapplicableagreement.Nopartofthisguidemaybereproduced
ortransmittedinanyformorbyanymeans,electronicormechanical,includingphotocopyingand
recordingforanypurposeotherthanthepurchaser’spersonalusewithoutthewrittenpermissionof
OneIdentityLLC.
TheinformationinthisdocumentisprovidedinconnectionwithOneIdentityproducts.Nolicense,
expressorimplied,byestoppelorotherwise,toanyintellectualpropertyrightisgrantedbythis
documentorinconnectionwiththesaleofOneIdentityLLCproducts.EXCEPTASSETFORTHINTHE
TERMSANDCONDITIONSASSPECIFIEDINTHELICENSEAGREEMENTFORTHISPRODUCT,
ONEIDENTITYASSUMESNOLIABILITYWHATSOEVERANDDISCLAIMSANYEXPRESS,IMPLIEDOR
STATUTORYWARRANTYRELATINGTOITSPRODUCTSINCLUDING,BUTNOTLIMITEDTO,THE
IMPLIEDWARRANTYOFMERCHANTABILITY,FITNESSFORAPARTICULARPURPOSE,ORNON-
INFRINGEMENT.INNOEVENTSHALLONEIDENTITYBELIABLEFORANYDIRECT,INDIRECT,
CONSEQUENTIAL,PUNITIVE,SPECIALORINCIDENTALDAMAGES(INCLUDING,WITHOUT
LIMITATION,DAMAGESFORLOSSOFPROFITS,BUSINESSINTERRUPTIONORLOSSOF
INFORMATION)ARISINGOUTOFTHEUSEORINABILITYTOUSETHISDOCUMENT,EVENIF
ONEIDENTITYHASBEENADVISEDOFTHEPOSSIBILITYOFSUCHDAMAGES.OneIdentitymakesno
representationsorwarrantieswithrespecttotheaccuracyorcompletenessofthecontentsofthis
documentandreservestherighttomakechangestospecificationsandproductdescriptionsatany
timewithoutnotice.OneIdentitydoesnotmakeanycommitmenttoupdatetheinformation
containedinthisdocument.
Ifyouhaveanyquestionsregardingyourpotentialuseofthismaterial,contact:
OneIdentityLLC.
Attn:LEGALDept
4PolarisWay
AlisoViejo,CA92656
RefertoourWebsite(http://www.OneIdentity.com)forregionalandinternationalofficeinformation.
Patents
OneIdentityisproudofouradvancedtechnology.Patentsandpendingpatentsmayapplytothis
product.Forthemostcurrentinformationaboutapplicablepatentsforthisproduct,pleasevisitour
websiteathttp://www.OneIdentity.com/legal/patents.aspx.
Trademarks
OneIdentityandtheOneIdentitylogoaretrademarksandregisteredtrademarksofOneIdentity
LLC.intheU.S.A.andothercountries.ForacompletelistofOneIdentitytrademarks,pleasevisit
ourwebsiteatwww.OneIdentity.com/legal.Allothertrademarksarethepropertyoftheir
respectiveowners.
Legend
WARNING: A WARNING icon indicates a potential for property damage, personal
injury, or death.
CAUTION: A CAUTION icon indicates potential damage to hardware or loss of data if
instructions are not followed.
IMPORTANT,NOTE,TIP,MOBILE,orVIDEO:Aninformationiconindicatessupporting
information.
SSBUserGuide
Updated-April2019
Version-5.3.0

Contents
Preface 5
Targetaudienceandprerequisites 5
Introduction 6
WhatSSBis 6
WhatSSBisnot 7
WhyisSSBneeded 7
WhousesSSB 8
SSB web interface 9
Supportedwebbrowsers 9
Searching log messages 11
Usingthesearchinterface 11
Customizingcolumnsofthelogmessagesearchinterface 18
Metadatacollectedaboutlogmessages 19
Usingcomplexsearchqueries 20
Searchingencryptedlogspaces 27
Usingpersistentdecryptionkeys 28
Usingsession-onlydecryptionkeys 29
Creating reports from log data 31
Creatingcustomstatisticsfromlogdata 31
Displayinglogstatistics 31
Creatingreportsfromcustomstatistics 34
Configuringcustomreports 35
Browsingreports 37
Creating content-based alerts 39
Settingupalertsonthesearchinterface 40
SettingupalertsontheSearch>Content-BasedAlertspage 42
Formatofalertmessages 44
About us 45
Contactingus 45
SSB 5.3.0 User Guide 3

1
Preface
Welcometothesyslog-ngStoreBox5.3.0UserGuide.
Thisdocumentdescribeshowtousethesyslog-ngStoreBox(SSB).Background
informationforthetechnologyandconceptsusedbytheproductarealsodiscussed.
Target audience and prerequisites
Thisguideisintendedforauditors,consultants,andsecurityexpertsresponsiblefor
auditing,monitoring,andtroubleshootingapplicationsandserveradministration
processes.ItisalsousefulforITdecisionmakerslookingforatooltoimprovethesecurity
andauditabilityoftheirservers,ortohelpcompliancewiththeSarbanes-Oxley(SOX),the
HealthInsurancePortabilityandAccountabilityAct(HIPAA),BaselII,orthePaymentCard
Industry(PCI)standard.
SSB 5.3.0 User Guide
Preface
5

2
Introduction
Thischapterintroducesthesyslog-ngStoreBox(SSB),discussinghowandwhyitisuseful,
andwhatbenefitsitofferstoanexistingITinfrastructure.
What SSB is
SSBisadevicethatcollects,processes,stores,monitors,andmanageslogmessages.Itis
acentrallogserverappliancethatcanreceivesystem(syslogandeventlog)logmessages
andSimpleNetworkManagementProtocol(SNMP)messagesfromyournetworkdevices
andcomputers,storetheminatrustedandsignedlogstore,automaticallyarchiveand
backupthemessages,andalsoclassifythemessagesusingartificialignorance.
ThemostnotablefeaturesofSSBareasfollows:
lSecurelogcollectionusingTransportLayerSecurity(TLS).
lTrusted,encrypted,andtimestampedstorage.
lAbilitytocollectlogmessagesfromawiderangeofplatforms,includingLinux,Unix,
BSD,SunSolaris,HP-UX,IBMAIX,IBMSystemi,aswellasMicrosoftWindows.
lForwardsmessagestologanalyzingengines.
lClassifiesmessagesusingcustomizablepatterndatabasesforreal-timelog
monitoring,alerting,andartificialignorance.
lHighAvailability(HA)supporttoensurecontinuouslogcollectioninbusiness-critical
environments.
lReal-timelogmonitoringandalerting.
lRetrievesgroupmembershipsoftheadministratorsandusersfromaLightweight
DirectoryAccessProtocol(LDAP)database.
lStrict,yeteasilycustomizableaccesscontroltograntusersaccessonlytoselected
logmessages.
lAbilitytosearchlogdatainmultiplelogspaces,whetheronthesameSSBapplicance
orlocatedonadifferentappliance,eveninaremotelocation.
SSBisconfiguredandmanagedfromanymodernwebbrowserthatsupportsHTTPS
connections,JavaScript,andcookies.
SSB 5.3.0 User Guide
Introduction
6

Supported browsers:
MozillaFirefox52ESR
WealsotestSSBonthefollowing,unsupportedbrowsers.ThefeaturesofSSBare
availableandusableonthesebrowsersaswell,butthelookandfeelmightbedifferent
fromthesupportedbrowsers.InternetExplorer11,MicrosoftEdge,andthecurrently
availableversionofMozillaFirefoxandGoogleChrome.
What SSB is not
SSBisnotaloganalyzingengine,thoughitcanclassifyindividuallogmessagesusing
artificialignorance.SSBcomeswithabuilt-infeaturetostorelogmessagepatternsthat
areconsidered"normal".Messagesmatchingthesepatternsareproducedduringthe
legitimateuseoftheapplications(forexamplesendmail,Postfix,MySQL,andsoon),and
areunimportantfromthelogmonitoringperspective,whiletheremainingmessagesmay
containsomething“interesting”.TheadministratorscandefinelogpatternsontheSSB
interface,labelmatchingmessages(forexample,securityevent,andsoon),andrequest
alertsifaspecificpatternisencountered.Forthoroughloganalysis,SSBcanalsoforward
theincominglogmessagestoexternalloganalyzingengines.
Why is SSB needed
Logmessagescontaininformationabouttheeventshappeningonthehosts.Monitoring
systemeventsisessentialforsecurityandsystemhealthmonitoringreasons.Awell-
establishedlogmanagementsolutionoffersseveralbenefitstoanorganization.Itensures
thatcomputersecurityrecordsarestoredinsufficientdetail,andprovidesasimplewayto
monitorandreviewtheselogs.Routinelogreviewsandcontinuousloganalysishelpto
identifysecurityincidents,policyviolations,orotheroperationalproblems.
Logsalsooftenformthebasisofauditingandforensicanalysis,producttroubleshooting
andsupport.Therearealsoseverallaws,regulationsandindustrialstandardsthat
explicitlyrequirethecentralcollection,periodicreview,andlong-timearchivingoflog
messages.ExamplesofsuchregulationsaretheSarbanes-OxleyAct(SOX),theBaselII
accord,theHealthInsurancePortabilityandAccountabilityAct(HIPAA),orthePayment
CardIndustryDataSecurityStandard(PCI-DSS).
Builtaroundthepopularsyslog-ngapplicationusedbythousandsoforganizations
worldwide,thesyslog-ngStoreBox(SSB)bringsyouapowerful,easy-to-configure
appliancetocollectandstoreyourlogs.Usingthefeaturesofthelatestsyslog-ngPremium
Editiontotheirfullpower,SSBallowsyoutocollect,process,andstorelogmessagesfrom
awiderangeofplatformsanddevices.
Alldatacanbestoredinencryptedandoptionallytimestampedfiles,preventingany
modificationormanipulation,satisfyingthehighestsecuritystandardsandpolicy
compliancerequirements.
SSB 5.3.0 User Guide
Introduction
7

Who uses SSB
SSBisusefulforeveryonewhohastocollect,store,andreviewlogmessages.In
particular,SSBisinvaluablefor:
lCentral log collection and archiving:SSBoffersasimple,reliable,andconvenient
wayofcollectinglogmessagescentrally.Itisessentiallyahigh-capacitylogserver
withhighavailabilitysupport.Beingabletocollectlogsfromseveraldifferent
platformsmakesiteasytointegrateintoanyenvironment.
lSecure log transfer and storage:Logmessagesoftencontainsensitiveinformation
andalsoformthebasisofaudittrailsforseveralapplications.Preventing
eavesdroppingduringmessagetransferandunauthorizedaccessoncethemessages
reachthelogserverisessentialforsecurityandprivacyreasons.
lPolicy compliance:Manyorganizationmustcomplywithregulationslikethe
Sarbanes-OxleyAct(SOX),theBaselIIaccord,theHealthInsurancePortabilityand
AccountabilityAct(HIPAA),orthePaymentCardIndustryDataSecurityStandard
(PCI-DSS).Theseregulationsoftenhaveexplicitorimplicitrequirementsaboutlog
management,suchasthecentralcollectionoflogmessages,theuseofloganalysis
topreventanddetectsecurityincidents,orguaranteeingtheavailabilityoflog
messagesforanextendedperiodoftime—uptoseveralyears.SSBhelpsthese
organizationstocomplywiththeseregulations.
lAutomated log monitoring and log pre-processing:Monitoringlogmessagesisan
essentialpartofsystem-healthmonitoringandsecurityincidentdetectionand
prevention.SSBoffersapowerfulplatformthatcanclassifytensofthousandsof
messagesreal-timetodetectmessagesthatdeviatefromregularmessages,and
promptlyraisealerts.Althoughthisclassificationdoesnotofferascompletean
inspectionasaloganalyzingapplication,SSBcanprocessmanymoremessages
thanaregularloganalyzingengine,andalsofilteroutunimportantmessagesto
decreasetheloadontheloganalyzingapplication.
SSB 5.3.0 User Guide
Introduction
8

3
SSB web interface
syslog-ngStoreBox(SSB)isconfiguredviathewebinterface.Configurationchangestake
effectautomaticallyafterclicking .Onlythemodificationsofthecurrentpageor
tabareactivated—eachpageandtabmustbecommittedseparately.
Supported web browsers
TheSSBwebinterfacecanbeaccessedonlyusingTLSencryptionandstrongcipher
algorithms.ThebrowsermustsupportHTTPSconnections,JavaScript,andcookies.Make
surethatbothJavaScriptandcookiesareenabled.
NOTE:
SSBdisplaysawarningmessageifyourbrowserisnotsupportedorJavaScriptis
disabled.
IfyouhavesuccessfullyaccessedtheSSBwebinterfaceusingHTTPSatleastonce,your
browserwillrememberthis,andonanysubsequentoccasions,itwillforceyoutoaccess
SSBusingHTTPS,evenifyoutryloadingitthroughanHTTPconnection.Thisisthanksto
theHTTPStrictTransportSecurity(HSTS)policy,whichenableswebserverstoenforce
webbrowserstorestrictcommunicationwiththeserveroveranencryptedSSL/TLS
connectionforasetperiod.WebserversdeclaretheHSTSpolicyusingaspecialStrict-
Transport-Securityresponseheaderfield.
Thismight,however,causeissuesinanyofthefollowingcases:
lWhentheSSLcertificateofSSB'swebinterfacehasexpired.Inthiscase,any
attempttoaccessthewebinterfaceusingasecureconnectionwillfailwithan
errormessage.
lWhenyouswitchthetrustedCA-signedcertificatetoaself-signedcertificatefor
SSB'swebinterface.AsperHSTSdesign,aself-signedcertificateisnottakento
havebeenissuedbyatrustedCA,thereforeanysecureconnectionstotheSSBweb
interfacewillfailwithanerrormessage.
Theresolutiontotheabove-mentionedissuesisto:
SSB 5.3.0 User Guide
SSB web interface
9

lRemovetheHSTSsettingsinyourbrowser.Thismustbedonelocally,ina
browser-specificway.Fordetailedinstructions,consultthesupportsiteofthe
browseryouareusing.
OR
lUploadanewcertificate,usingadifferentbrowseronadifferentmachine.For
detailedinstructionsonhowtouploadexternalcertificatestoSSB,see"Uploading
externalcertificatestoSSB"intheAdministrationGuide.
Supported browsers:
MozillaFirefox52ESR
WealsotestSSBonthefollowing,unsupportedbrowsers.ThefeaturesofSSBare
availableandusableonthesebrowsersaswell,butthelookandfeelmightbedifferent
fromthesupportedbrowsers.InternetExplorer11,MicrosoftEdge,andthecurrently
availableversionofMozillaFirefoxandGoogleChrome.
SSB 5.3.0 User Guide
SSB web interface
10

4
Searching log messages
ThissectiondescribeshowtobrowsethelogmessagescollectedonSSB.
lUsingthesearchinterfaceonpage11explainshowtouseandcustomizethesearch
interface,describesthelogmessagedatathatisavailableonSSB,andprovides
examplesofthethewildcardandbooleansearchoperatorsyoucanuse.
lSearchingencryptedlogspacesonpage27describeshowtodecryptandbrowse
encryptedlogspaces.
Using the search interface
SSBhasasearchinterfaceforbrowsingthecollectedlogmessages.Youcanchoosethe
logspace,enterasearchexpression,specifythetimeframe,andbrowsetheresultshere.
Thissectionwalksyouthroughthemainpartsofthesearchinterface.
Toaccessthesearchinterface,navigatetoSearch > Logspaces.
SSB 5.3.0 User Guide
Searching log messages
11

Figure 1: Search > Logspaces — The log message search interface
Logspaces:
Tochoosetheappropriatelogspace,usetheLogspace namemenu.Notethatyoucannot
accessplaintextlogspacesontheSSBsearchinterface.
Formoreinformationontheavailablelogspaces,andhowtoconfigurethem,see"Storing
messagesonSSB"intheAdministrationGuide.
Search:
Onthelogmessagesearchinterface,youcanusetheSearch expressionfieldtosearch
thefulllistoflogmessages.Searchexpressionsarecaseinsensitive,withtheexceptionof
operators(likeAND,OR,etc.),whichmustalwaysbecapitalized.Clickthe icon,orsee
Usingcomplexsearchqueriesformoredetails.
Whensearchinglogmessages,thecapabilitiesofthesearchenginedependonthe
delimitersusedtoindextheparticularlogspace.Fordetailsonhowtoconfigurethe
delimitersusedforindexing,see"Creatinglogstores"intheAdministrationGuide.
NOTE:
Youcansearchinindexedlogspaceseveniflogtrafficisdisabled.
Youcancreatecomplexsearchesusingwildcardsandbooleanexpressions.Formore
informationandpracticalexamples,seeUsingcomplexsearchqueries.
SSB 5.3.0 User Guide
Searching log messages
12

NOTE:
SSBonlyindexesthefirst59charactersofeveryname-valuepair(parameter).This
hastwoconsequences:
lIftheparameterislongerthan59characters,anexactsearchmightdeliver
multiple,impreciseresults.
Considerthefollowingexample.Iftheparameteris:
.sdata.security.uid=2011-12-08T12:32:25.024+01:00-hostname-12345
SSBindexesitonlyas:
.sdata.security.uid=2011-12-08T12:32:25.024+01:00-hostname-
Thiscorrespondstothefirst59characters.Asaresult,searchingfor:
nvpair:.sdata.security.uid=2011-12-08T12:32:25.024+01:00-hostname-12345
returnsalllogmessagesthatcontain:
.sdata.security.uid=2011-12-08T12:32:25.024+01:00-hostname-
lUsingwildcardsmightleadtotheomissionofcertainmessagesfromthe
searchresults.
Usingthesameexampleasabove,searchingforthevalue:
nvpair:*=2011-12-08T12:32:25.024+01:00-hostname-12345
doesnotreturnanyresults(asthe12345partwasnotindexed).Instead,you
havetosearchfor:
nvpair:*=2011-12-08T12:32:25.024+01:00-hostname-*
This,asexplainedabove,mightfindmultipleresults.
Overview:
Displaysthenumberoflogmessagesintheselectedtimeinterval.
Figure 2: Search > Logspaces — Log message overview
Usethe and iconstozoom,andthearrowstodisplaythepreviousorthenext
intervals.Tochangethetimeframe,youcan:
lChangethebeginningandtheenddate.
lClickanddragthepointeracrossaperiodonthecalendarbarstoselectaspecific
SSB 5.3.0 User Guide
Searching log messages
13

intervalandzoomin.
lUse the Jump to last option to select the last 15 minutes, hour, 6 hours,
day, or week.
Hoveringthemouseaboveabardisplaysthenumberofresults,andthestartandenddate
oftheperiodthatthebarrepresents.Clickabartodisplaytheresultsofthatperiodinthe
table.UseShift+Clicktoselectmultiplebars.
Action bar:
Thesearchinterfaceprovidesanactionbarthatallowsyouto:
lFetchalinktoasearchquery.
lExportsearchresultsintoacsvfile.
lCreateacontent-basedalert.
Italsodisplaysthefollowinginformation:
lErrorandwarningmessages.
lThenumberofsearchresultsreturnedbyasearchquery.
Figure 3: Search > Logspaces: Action bar
Link to a search query:
Onclicking ,theBookmark linkspanelisdisplayed:
Figure 4: Search > Logspaces — Bookmark links panel
Bookmarklinksallowyoutofetchalinktoasearchquerysothatyoucan:
lShareyoursearchquerieswithcolleagues,whocanthenaccesstherelevantsearch
resultsinoneclick.
lSavefrequentlyusedsearchqueriesasbookmarklinks.
ThelinkintheCurrent viewfieldprovidesadirectlinktoyoursearchqueryandits
resultscurrentlydisplayedonyourscreen.Wheneveryouopenthebookmarkedlinkfrom
yourbrowser,itwillalwaysreturnthesame,fixedsetofresults.Thestartandenddate
SSB 5.3.0 User Guide
Searching log messages
14

thatyousetwhenexecutingthesearchqueryandfetchingthelinkfromtheBookmark
linkspanelremainfixed.
TheLastmenu,ontheotherhand,allowsyoutospecifyanintervaloftime,forexample,
thelast15minutesorthelasthour,andfetchsearchresultsgeneratedwithinthatperiod.
Thesearchresultsthatyouaccessusingthislinkmaydifferontwodifferentoccasionsas
thestartpointofthespecifiedintervalisalwaysthemomentyouopenthebookmarked
linkfromyourbrowser.
CSV export:
Onclicking ,theCSV exportpanelisdisplayed:
Figure 5: Search > Logspaces — CSV export panel
Clicking exportsyoursearchresultsintoaCSVfile.Thissavesthe
tableasatextfilecontainingcomma-separatedvalues.Notethatifanerroroccurswhen
exportingthedata,theexportedCSVfilewillincludealine(usuallyasthelastlineofthe
file)startingwithazeroandthedetailsoftheproblem,forexample,0<description_of_
the_error>.
CAUTION:
Do not use Download CSV export to export large amounts of data, as
exporting data can be very slow, especially if the system is under heavy
load. If you regularly need a large portion of your data in plain text
format, consider using the SSB RPC API (for details, see "The SSB RPC
API" in the Administration Guide), or sharing the log files on the network
and processing them with external tools (for details, see "Accessing log
files across the network" in the Administration Guide).
Alert:
Thealertfunctionalityenablesyoutosetupcontent-basedalertsforsearchexpressionsof
yourchoice.Youwillreceiveanalertwhenamatchisfoundbetweenthesearchexpression
andthecontentsofalogmessage.Notethatthealertsaregeneratedforonlythoselog
messagesthatarestoredinthelogspace(s)forwhichyousetupthealert.
Fordetailedinformationoncontent-basedalerts,see"Creatingcontent-basedalerts"inthe
AdministrationGuide.
Errors and warnings:
Whenanyuseractionresultsinanerrorcondition(forexample,ifyouenteraninvalid
searchexpression,displaystatisticsforacolumnthathasnotbeenindexed),anerroror
SSB 5.3.0 User Guide
Searching log messages
15

warningnotificationwillbedisplayedontheactionbar.Errorsareshowninredletters,
warningsaredisplayedinamber.
Ifthereismorethanonenotification,thelatestwillbedisplayedandthenumberof
notificationstriggeredwillalsobeindicated.ClickingthenotificationwillopenanErrors
and warningspanel:
Figure 6: Search > Logspaces — Errors and warnings panel
TheErrors and warningspaneldisplaysalistoferrors/warningswiththeirtimestamp
anddetailsoftheircause.
Youcanclearnotificationsonebyonebyclicking nexttothethem,orclearallofthem
byclicking .
Search results:
Afterrunningasearchquery,theactionbardisplaysthenumberofsearchresultsreturned
bythequery.Thisisusefulinformationwhenyouaretryingtofindouthowoftenacertain
elementappearsinthelogs.
List of log messages:
UsethearrowkeysandthePage UpandPage Downkeystonavigatethelistedlog
messages,orusethemousewheeltoscroll.Youcandisablemousewheelscrollinginyour
User menu > Preferences.Ifdataistoolongtofitononeline,itisautomatically
wrappedandonlythefirstlineisdisplayed.
SSB 5.3.0 User Guide
Searching log messages
16

Figure 7: Search > Logspaces — List of log messages
Details of a log message:
To expand a row in the list of log messages, click . The complete log message is
displayed:
Figure 8: Search > Logspaces — Viewing a single log message
Usethearrowkeystojumptothepreviousorthenextlogmessage.
UsethePage UpandPage Downtojumptothe10thlogmessagebeforeorafterthecurrently
displayedlogmessage.Youcanalsojumptothepreviousorthenextlogmessagewiththe
mousewheel.
Ifthedisplayedlogmessageconsistsofseveralpagesofdata,youcanconfigurethe
mousewheeltobeabletouseitforscrollingthemessagevertically.Todothis,navigate
toUser menu > Preferences,deselectMousewheel scrolling of search resultsand
clickSet options.Thiswilldisablejumpingbetweenlogmessageswiththemousewheel.
Youcanperformthefollowingactions:
lClickanywordinthemessagetocopyittotheSearchfield.
lClickanyofthedynamiccolumns(name-valuepairs)toadditasacolumntothelist
SSB 5.3.0 User Guide
Searching log messages
17

oflogmessages.
lClickanyofthe iconstoviewthestatisticsoftheselectedcategory.
Toreturntothelistofalllogmessages,click .
Customizing columns of the log message
search interface
The following describes how to customize the data displayed on the log message
search interface.
To customize the data displayed on the log message search interface
1. ClickCustomize columns.
Theparametersusedforthecolumnswhendisplayinglogmessagesarelistedunder
Displayed columns.AllotheravailableparametersarelistedunderAvailable
static columnsandAvailable dynamic columns.
Dynamiccolumnsarecreatedfromstructureddataparameters(name-valuepairs)
inlogmessagesstoredonSSB.Structureddataparametersaredetectedandadded
tothelistofcustomizablecolumnsautomatically.(Formoreinformationonthe
structureddatapartoflogmessages,see"TheSTRUCTURED-DATAmessagepart"in
theAdministrationGuide.)
NOTE:
ToexportthesearchresultsintoaCSVfile,click ontheactionbar.Note
thattheCSVfileincludesallthestaticcolumnsandthedisplayeddynamic
columns.
SSB 5.3.0 User Guide
Searching log messages
18

Figure 9: Search > Logspaces > Customize columns — Customizing
columns of the log message search interface
2. ToaddastaticcolumntotheDisplayed columns,click .
3. ToaddadynamiccolumntotheDisplayed columns,chooseaname-valuepair
fromAvailable dynamic columnsandclick .
Theselectednamegeneratesanew,separatedynamiccolumnwitha<name>
heading(where<name>isthenameofthekey).Therelevantvaluesaredisplayed
inthecellsoftherespectivecolumn.
4. ToremoveparametersfromtheVisible columns,click .
5. Todisplaythefullcontentofeachcolumn(includingthelogmessages),enableShow
full content of columns.
Metadata collected about log messages
Thefollowinginformationisavailableaboutthelogmessages:
lProcessed Timestamp:ThedatewhenSSBreceivedthelogmessageinYEAR-MONTH-
DAY HOUR:MINUTE:SECONDformat.
lTimestamp:Thetimestampreceivedinthemessage—thetimewhenthelog
messagewascreatedinYEAR-MONTH-DAY HOUR:MINUTE:SECONDformat.
lFacility:Thefacilitythatsentthemessage.
lPriority:Thepriorityvalueofthemessage.
lProgram:Theapplicationthatcreatedthemessage.
lPid:Theprogramidentifieroftheapplicationthatcreatedthemessage.
lHost:TheIPaddressorhostnameoftheclientthatsentthemessagetoSSB.
SSB 5.3.0 User Guide
Searching log messages
19

lMessage:Thetextofthelogmessage.
lTag:Tagsassignedtothemessagematchingcertainpatterndatabaserules.
lId:UniqueIDofthemessage.
lclassifier.rule_id:IDofthepatterndatabaserulethatmatchedthemessage.
lclassifier.class:Descriptionofthepatterndatabaserulethatmatchedthemessage.
lDynamic columns, created from additional name-value pairs, might also be
available.
Using complex search queries
Youcanusewildcardsandbooleanexpressions,andsearchspecificpartsofthelog
messagescollectedonSSB.
NOTE:
Whensearchinglogmessages,thecapabilitiesofthesearchenginedependonthe
delimitersusedtoindextheparticularlogspace.Bydefault,theindexerusesthe
followingdelimitercharacterstoseparatethemessageintowords(tokens):& : ~ ?
! [ ] = , ; ( ) ' ".Fordetailsonhowtoconfigurethedelimitersusedforindexing,
see"Creatinglogstores"intheAdministrationGuide.
NOTE:
Itisnotpossibletosearchforthewhitespace( )characterintheMESSAGEpartof
thelogmessage,sinceitisahard-codeddelimitercharacter.
Thefollowingsectionsprovideexamplesfordifferentsearchqueries:
lForexamplesofexactmatches,seeSearchingforexactmatchesandusingcomplex
queriesonpage20.
lForexamplesofusingbooleanoperatorstocombinesearchkeywords,see
Combiningsearchkeywordsonpage21.
lForexamplesofwildcardsearches,seeUsingwildcardsearchesonpage22.
lForexamplesofsearchingforspecialcharacters,seeSearchingforspecial
charactersonpage24.
lForexamplesofsearchinginaspecificpartofthemessage,seeSearchingina
specificpartofthemessageonpage25.
lForexamplesofsearchingname-valuepairs,seeSearchingthename-valuepairsof
themessageonpage25.
Searching for exact matches and using complex queries
Bydefault,SSBsearchesforkeywordsaswholewordsintheMESSAGEpartofthelog
messageandreturnsonlyexactmatches.
SSB 5.3.0 User Guide
Searching log messages
20
Table of contents
Popular Storage manuals by other brands

Crafstman
Crafstman CMXMSAJ94995 instruction manual

Dell
Dell PowerVault 132T LTO Handbook

HP
HP Alletra 4120 Product End-of-Life Disassembly Instructions

Dot Hill Systems
Dot Hill Systems AssuredSAN 6004 Cli reference guide

ACP-EP Memory
ACP-EP Memory ACP-EP Product sheet

IBM
IBM Cloud Object Storage System Slicestor 2212... Appliance Manual

Hallowell
Hallowell 400 Series Assembly Instructions/Parts Manual

Cavalry
Cavalry CAUPT25160 user manual

Hama
Hama Vilitas FlashPen USB 3.0 Operating instruction

Fujitsu
Fujitsu Eternus DX80 S2 manual

ioSafe
ioSafe SoloPRO eSATA/USB 2.0 user manual

Western Digital
Western Digital My Passport WDML2500 user manual