...
The Events Toolbar includes the following elements:
Element | Description | ||
---|---|---|---|
/ | Expand all Events / Collapse all Events icons. Clicking the icon the icon expands all events to display all their column names and respective values; clicking the icon collapses all events to show only some of the column names and respective values. | / | Disable Analytics / Enable Analytics icons. Clicking the icon disables Analytics for all events; clicking the icon enables Analytics for all events. |
Events Area
The Events Area includes a list of events resulting from the search, where each event contains the following elements:
Element | Description |
---|---|
Event timestamp | The date and time that the event occurred, in the format MM/DD/YYYY HH:MM:SS |
Analytics layer | If Analytics is active, colors the fonts of the column values that Analytics detects as problematic, according to the following color-coding:
Under the timestamp, displays the severity of the most severe column value detected by Analytics in the event: high, medium, low, or none. |
Event structure | The structure of the event, including its column names and respective column text, in the format ([COLUMN_NAME] COLUMN_TEXT). |
Event source fields | Shows the source of the event – the log, server, and/or applications which generated the event. Mouse over on the log source indicator [Log] presents the full path of the source log that this message originates from. |
Expand Event icon. Appears at the end of an event that can be expanded to show all its column names and respective values. Clicking the icon the icon expands the event to display all its column names and respective values, and changes the icon to the Collapse Event icon , so that it can be shortened at a later time. | |
Mouse Over Options | Mouse over on search results (and columns names) presents two optional action: Search Actions - Clicking this icon presents a list of possible search actions on the highlighted phrase: append to current search using AND, append to current search using OR, excluding from current search, replacing the current search. Data Markers - Clicking this icon presents colors to be selected in order to mark the highlighted phrase. |