Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: Migrated to Confluence 5.3

Welcome to XpoLog 4.5

...

Known Issues for the Current Version

  1. Log type FTP is no longer available (use SSH/SFTP instead).
  2. Log type HTTP is no longer available.

 

Anchor
general
general

General System Enhancements

Anchor
general-storage
general-storage

Storage Capacity Utilization 

XpoLog automatically collects all data from the remote log sources. Stored data is maintained (compressed) in a searchable repository for as long as needed. Required capacity is 30%-40% of the original log data.

 

Anchor
general-data
general-data

Data Model Optimization 

XpoLog data model management was redesigned to run in maximum efficiency and return results within seconds, from thousands of log sources and terabytes of log data.

 

Anchor
general-performance
general-performance

Performance 

XpoLog 4.5 storage utilization optimization and new data model design significantly improve data availability and performance, returning results super-fast.

 

Anchor
general-scalability
general-scalability

Scalability and Stability 

Comprehensive enhancements were implemented to increase stability and enable a MapReduce approach for high scalability to support huge logs volume.

 

Anchor
general-ui
general-ui

UI Changes  

General UI changes were implemented, including renaming of system modules: XpoLog to Manager and XpoSearch to Search.


 

Anchor
manager
manager


XpoLog Manager

Anchor
manager-online
manager-online

Logs Configuration Management

Online sources management is now integrated with collected sources management. Collectors management console and Storage panel have been removed to simplify configuration management.
There now exists a single configuration and access to a log source under Folders and Logs, with the relevant collection policy
.

 

Anchor
manager-parsing
manager-parsing

Automatic Data Parsing and Normalization

A major enhancement has been made to the patterns recognition process in order to automatically identify and normalize data into a structured model. This improvement enables a complete scan of remote log sources to get the data available in XpoLog very quickly. Further tuning of the normalization/parsing rules is available at any given time.


Anchor
manager-configuration
manager-configuration

Automated Configuration Changes Procedures

  • Apply a naming convention on multiple logs in the environment so that log sources have a unified naming convention; for example, <server_name>_<folder_name>_<log_name>

 

Anchor
manager-parsing
manager-parsing

UI Changes

Several UI changes were implemented in XpoLog Manager.

 


Anchor
search
search

XpoLog Search

Anchor
search-augmented
search-augmented

Augmented Search

Integration of knowledge layers on top of regular search results. The knowledge layers contain auto-detected problems (automatically identified by the system’s Analytics engine), predefined problems (users' custom problems saved in the system), and will contain more knowledge types in the future. The problems suggestions are presented over time, based on severity and number of occurrences, and can be accessed immediately. More> 

 

Anchor
search-visualization
search-visualization

Ad-hoc Visualizations

Options have been added to create data visualization based on queries results, directly in the search console – line, bar and stack graphs, pie charts, events lists, and more. More>

 

Anchor
search-dashboards
search-dashboards

Dashboards Integration

Integration has been added between the Search console and dashboards – any visualization can now be saved from the search directly into an existing or new dashboard. More>

 

Anchor
search-pdf
search-pdf

Integrated PDF Generation

 PDF generation is now integrated directly from a search view to export results. More>

 

Anchor
search-commands
search-commands

New Search Commands and Functions

XpoLog Search 4.5 includes the following new search commands:

  • Execute – programmatic syntax that provides users the option to execute highly complex data querying
  • Transaction – an events correlations mechanism for querying transactions events correlated from multiple sources
  • Where – constraints syntax on top of queries for applying thresholds and filtering the results accordingly
  • Time – a time measurement function between events, based on a common parameter (time distance between first occurrence to last)
  • Custom formatting – automated and custom formatting of different units of time, volumes, and more. For example, takes a numeric value which represents a volume unit, and formats it to be presented in a volume unit of bytes, Kilobytes, Megabytes, etc.

 

Anchor
search-tools
search-tools

User Tools to Build Queries, Zoom In, and Drill Down

New tools and options are included in the new Search console:

  • Query tools (regular searches) – Added tools to add values from search results to queries, exclude from search results, replace search, and add to search to provide a more user friendly and efficient workflow on the search console.
  • Query tools (complex searches) – Added Interesting Fields section to create complex queries (aggregations, statistics, and additional functions) with the click of a button.
  • Zoom-in – Enhanced the zoom-in capabilities of the search to seconds resolution by selecting the desired time range directly on the graph. Also added a new time graph that shows the graph for the original search time range, with the zoomed-in part of the graph highlighted. This enables viewing the zoomed-in part of the graph relative to the original search time graph. 

Anchor
search-streaming
search-streaming

Data Streaming


Anchor
search-performance
search-performance

Performance

Major search optimizations have been added to isolate matching events in the environment within seconds.


Anchor
search-ui
search-ui

UI Changes

The search console UI was thoroughly redesigned to include all of the above new functionality.

 

Anchor
dashboards
dashboards

XpoLog Dashboards

Anchor
dashboards-html5
dashboards-html5

HTML5

All charts were replaced with HTML5 (formerly it used Flash). The only gadget that uses Flash is GeoIP map.


Anchor
dashboards-pdf
dashboards-pdf

Integrated PDF Generation

PDF generation is now integrated directly from a dashboard view or a specific gadget view. In addition, you can now schedule an automated process to send out a snapshot of dashboards as PDF.


Anchor
dashboards-api
dashboards-api

External Exposure of Dashboards 

XpoLog exposes a direct link to dashboards and specific gadgets to enable using the dashboard’s definition in external systems and consoles.


Anchor
dashboards-visualization
dashboards-visualization

Additional Gadgets – Visualization Options

New gadget types include pie and donut charts, stack bars, transactions visualization, and more.