Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

The contents of the Search Results Area depends on the type of search that you perform:

  • For a simple search, each result event is displayed.
  • For a complex search, a summary table of the result events is displayed.

Simple Search Results Area

The following table describes the user interface of the Simple Search Results Area:

Element

Description

  Events toolbar

Search Results Summary Panel

A panel that summarizes the results of the search, and provides navigation to the result event pages.

Events Toolbar

Includes icons for

defining the graph display and content.

expanding/collapsing events and controlling the view format

Events Area

A

graph with the timeline selected in the search query in the x-axis, and

list of the events that match the search query.

Search Results Summary Panel

The Search Results Summary Panel includes the following details:

Element

Description

Search Summary

In the case of a simple search, displays the number of matching log events

in the y-axis.

The graph shows the distribution of events matching the search query over the selected timeline. In each timeslot, provides a zoom-in icon Image Removed for zooming into the timeslot. After zooming in, provides a zoom-out button for returning to previous zoom level.

Image Removed, Image RemovedSelecting these buttons located in the left and right edges below the graph, displays the distribution of matching events in the previous/next timeslot.

 

Graph Toolbar

The Graph toolbar includes the following elements:

 

ElementDescriptionImage RemovedSelecting this icon displays a line graph of the event distribution.Image Removed

Selecting this icon displays a bar graph of the event distribution.

Image RemovedSelecting this icon displays the event distribution originating from each log, separately. Image RemovedSelecting this icon displays a summary view of the event distribution from all the logs

, the number of source logs of these events, and the period of time searched.

In the case of a complex search, displays the number of results in the table, the number of events that the results are based on, the number of source logs of these events, and the period of time searched.  

Image Added

Paging in case of multiple events in the result

Events Toolbar

The Events Toolbar includes the following elements:

Element

Description

Image Added

Expand all Events / Collapse all Events icons.

Clicking the icon expands all events to display all their column names and respective values.

Image Added

Display mode - Raw data, Table formatted data, Parsed data.

Image Added

use the menu (access via the 3 dots menu) to control the way you would like to display the events:

  • Raw data - data as read from source

  • Parsed - data parsed based on XPLG pattern(s) applied it

  • Table - table formatted view

Events Area

The Events Area includes a list of events resulting from the search, where each event contains the following elements:

Element

Description

Event timestamp

The date and time that the event occurred, in the format MM/DD/YYYY HH:MM:SS

Image Added

The icon is always displayed next to each event’s timestamp allowing multiple options to copy or export specific event’s data -

Image Added

Analytics layer

If Analytics is active, colors the fonts of the column values that Analytics detects as problematic, according to the following color-coding:

  • Red – high severity problem

  • Orange – medium severity problem

  • Yellow – low severity problem

Under the timestamp, displays the severity of the most severe column value detected by Analytics in the event: high, medium, low, or none.

Event source fields

Shows the source of the event – the log, server, and/or applications which generated the event. Mouse over on the log source indicator [Log] presents the full path of the source log that this message originates from.

Image Added

Expand Event icon.

Appears at the end of an event that can be expanded to show all its column names and respective values. 

Clicking the icon expands the event to display all its column names and respective values.

Mouse Over Options

Mouse over on search results (and columns names) presents two optional action:

Search Actions - Clicking this icon presents a list of possible search actions on the highlighted phrase: append to current search using AND, append to current search using OR, excluding from current search, replacing the current search.
It is also possible to mark specific part of an event/string and these options will be available on the selected part.

Image Added

Next to each event, when mouse overing it, these options will be displayed on the right hand side.

Image Added

Zoom in to view the event in the dedicated log viewer (a new browser tab will be opened and the event will be highlighted)

Image Added

Open an event explorer to view the event’s contents in multiple formats

Image Added

Zoom in to Analytics screen.