Académique Documents
Professionnel Documents
Culture Documents
Queries
Queries are the most powerful feature of Sentinel Log Manager Queries are used to
Powerful for forensics and research Queries can be saved as reports Lucene Query Language
>
Lucene Overview
Open source software http://lucene.apache.org/ Provides scalable, high-performance indexing Provides powerful, proven accurate, efficient search algorithms
ranked searching -- best results returned first many powerful query types: phrase queries, wildcard queries, proximity queries, range queries and more fielded searching (e.g., title, author, contents) date-range searching sorting by any field multiple-index searching with merged results allows simultaneous update and searching
Works on words <field tag>:search string These need to be in UPPERCASE in the query AND, OR (default), NOT Appendix Apache Lucene Query Parser Syntax
See Search Tips link Review with instructor Only tags can be used in queries
Basic Queries
No tag UTC time should be synchronized for queries to function properly Synchronization across client running query, server and event sources is required
Basic Search
Advanced Queries
You can pick specific / additional fields Sorting method Uses AND to append additional conditions Top 10 or bottom 10 unique values can be drilled down to
Refining Queries
Refining Queries
1 0
Refine a Query
1 1
Refine a Query
1 2
Results can be exported in zipped CSV format Results can be send to an action Queries can be saved as Reports
1 3
Lab Exercise
Change landing page to sev:[0 TO 5] and the last hour Create a query for the word root with no time limits Create a query where product name not Generic Event Collector Building on the query add event name is unsupported event Building on the query add also event name is collector message Export results
1 4