22
Sentinel Log Manager 1.0.0.4 Administration Guide
no
vd
ocx
(e
n)
19
Fe
bru
a
ry
20
10
The time-based raw data files are closed (changed to read-only) after a duration and no more events
are written to them. After these files are closed, they are compressed and archived to the configured
location.
“Raw Data Storage” on page 22
“Raw Data Representation” on page 23
Raw Data Storage
In Sentinel Log Manager, raw data is always stored. Raw data partitions are individual files. They
are created every hour, and are closed within 10 minutes after the elapsed time. When a raw data file
is closed, it is renamed to identify the closed files. Files in the open state have a
.open
extension.
When they are closed, they will be renamed to have a
.log
extension. Sometime after they are
closed, they will be compressed and will then have a
.zip
extension. After being compressed, they
are moved to archive storage and are no longer present in the local storage.
The following table describes the directory structure of the online raw data under the installation
directory:
Table 3-1
Raw Data Directory Structure
Directory structure
Description
/data
The primary directory for all data storage.
/data/rawdata
The sub directory where all raw data is stored.
/data/rawdata/
online
The directory where all the online raw data is stored.
/data/rawdata/
EventSource UUID
The sub directory name is the universally unique identifier (UUID) of the
event source (for example, E20D0840-1E0A-102C-9F30-000C2949BA91).
There is one subdirectory for each event source under the
online
subdirectory. That subdirectory contains all raw data received from that
event source.
/data/rawdata/
EventSource UUID/
Month
The subdirectory name is in the yyyy-mm format (for example: 2009-05 is
May of 2009).
Data in the event source subdirectory is partitioned by month. Each month
has its own subdirectory.
Summary of Contents for SENTINEL LOG MANAGER 1.0.0.5 - 03-31-2010
Page 4: ...4 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Page 46: ...46 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Page 74: ...74 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Page 140: ...140 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Page 146: ...146 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Page 148: ...148 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Page 158: ...158 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Page 166: ...166 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Page 168: ...168 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...