Configuring Data Storage
23
no
vd
ocx
(e
n)
19
Fe
bru
a
ry
20
10
Raw Data Representation
Each raw data event is represented as a single line in a raw data file. Each line is a JSON object that
has the following fields:
Table 3-2
Raw Data Representation
/data/rawdata/
EventSource UUID/
Month/1 Hour Data
Files
Each file in the
Month
directory contains data received during a specific
one-hour period. Most data in the file have a time stamp that are within the
one-hour period.
The name of the file indicates the day of the month and the one-hour period
that is represented.
The filename format is dd-hhmm.extension.
Where:
dd
is the day of the month.
hh
is the hour of the day.
mm
is the minute of the hour.
extension is either
open
or
log
or
zip
(compressed).
For example:
A name with the extension
08-1300.open
indicates that the file contains
uncompressed data received on the 8th day of the month between 01.00
p.m. and 02.00 p.m.
A name with the extension
08-0900.log
indicates that the file contains
uncompressed data received on the 8th day of the month between 09.00
a.m. and 10.00 a.m., and the file is closed, but not yet compressed.
A name with the extension
08-0000.zip
indicates that the file contains
compressed data received on the 8th day of the month between 12:00 a.m.
and 01:00 a.m.
The following examples show filenames as they might appear relative to the installation directory:
data/rawdata/online/E20D0840-1E0A-102C-9F30-000C2949BA91/2009-05/08-
0000.zip
: Compressed raw data received on May 8, 2009 between 12:00 a.m. and 01:00 a.m.
data/rawdata/online/E20D0840-1E0A-102C-9F30-000C2949BA91/2009-05/08-
0100.open
: Uncompressed raw data received on May 8, 2009 in every hour.
Field Name
Description
EventDate
This is the date and time when the Sentinel Log Manager received this
event and not the date and time when the event has occurred.
Example: “05/07/2009 05:23.790”
Directory structure
Description
Summary of Contents for SENTINEL LOG MANAGER 1.0.0.5 - 03-31-2010
Page 4: ...4 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Page 46: ...46 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Page 74: ...74 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Page 140: ...140 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Page 146: ...146 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Page 148: ...148 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Page 158: ...158 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Page 166: ...166 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Page 168: ...168 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...