App - Linux

 

Name

Linux

Versions

N/A

Type

Operating System

Logtypes

linux, cron, mail, messages

 

In order to deploy the Linux App use the following page to prepare the log data - Preparing Linux Event Logs Data.

Deploying the App

  1. Deploy the Linux App available in the XpoLog Linux setup or by getting the App package from XpoLog website.

  2. Once the App is successfully deployed (by default) all logs tagged in logtype: linux, cron, mail, messages will be included in the App. To change that simply edit the App and specify which logs to include or exclude.

Open and Use the App

  1. Click on the deployed App

  2. When the App will open you will see a list of available predefined dashboards. In each dashboard you can find a set of visualization widgets, rules and searches that analyze the Linux event logs. 

Linux Dashboards and Widgets

The Linux application contains a set of dashboards:

  • Overview - a general overview of the Linux environment including event sources, login status, and security status.

  • Events Sources - a console that enables events view from selected servers/domains/logs

  • Activity - logging activity of servers and processes over time last 1 day vs. last 7 days

  • Login Status - users activity review such as logons over time, success vs. failure authentication, failed logins, etc.

  • Problems & Errors - a report of applications problems by event/host

  • Cron - a console for the cron activities.

  • Mail - a console for the mail activities.

Use the user inputs while viewing a dashboard to filter the view to the desired values such as servers, logs, processes, etc.