Searching
81
no
vd
ocx
(e
n)
19
Fe
bru
a
ry
20
10
2. If there are more than 50,000 events, the event field statistics will be calculated only on
the first 50,000 events.
There could be an event field value that occurs 50 times in the first 50,000 events, but it
could occur 1,000 times in all other stored events. So, in the above scenario the displayed
value count would be 50, but when the search is refined with this value it would return
1,000 events.
6
Click each event field to view the unique values for that event field.
For example, if the search results contained events that had severities 1, 2, 5, and 4, then the
event field will be displayed as
Severity (4)
.
The top 10 unique values are initially displayed in the order of most frequent to least frequent.
The value next to the check box represents the unique value for that event field and the value at
the far right side represents the number of times the value appears in the search result.
If there are multiple unique values occurring at the same number of times in a search, then the
values are ordered by the most recent occurrence of the value.
For example, if events of severity 1 and 4 occurred 34 times in the search results, of which an
event of severity 4 was logged most recently, then the unique value 4 would appear at the top of
the list.
7
To save the selected unique values in the search refinement term popup, click
OK
.
8
To display the unique values in the order of least frequent to most frequent, click
reverse.
NOTE:
When there are more than 10 unique values, you can view and filter either the top 10 or
the bottom 10 unique values. You are not allowed to refine your search on both the conditions
at the same time.
9
Select one or more of the unique value check boxes to refine the search results for the particular
event field, and then click
Save.
Selected event field values are listed under the event field in
the
REFINE
pane.
The right pane displays the refined search results, which only contains the selected values.
Содержание SENTINEL LOG MANAGER 1.0.0.5 - 03-31-2010
Страница 4: ...4 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Страница 46: ...46 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Страница 74: ...74 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Страница 140: ...140 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Страница 146: ...146 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Страница 148: ...148 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Страница 158: ...158 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Страница 166: ...166 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Страница 168: ...168 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...