Skip to main content

Responses are generated using AI and may contain mistakes.

Log StreamLog Stream Guide

Parser Calibration Tiers

Exabeam defines how well an event is aligned to the Common Information Model by determining how many of the Core, Detection, and Information fields were extracted for each parsed log line.

This metric is aggregated for the previous 24 hours per parser, and the parser is then assigned to a Parser Calibration Tier based on this assessment according to the following formula:

  • Tier 1 - The log is parsed and an Event is built for more than 70% of the Core, Detection, and Informational fields in an event.

  • Tier 2 - The log is parsed and an Event is built for less than 70% of the Core, Detection, and Informational fields in an event

  • Tier 3 - The log is parsed but no Event is defined for this log type or Event Builder conditions are not met.

  • Tier 4 - The log is unparsed but available for search, correlation, and retention/storage.

On the Parsers Overview tab of the Log Stream home page, calibration tier assignments for each parser are shown in a column of the parser list at the bottom of the page.

Additional calibration tier information is displayed at the top of the page in two graphical representations that you can toggle between:

  • Tier Distribution – This graphic shows what percentage of all your parsers have been assigned to each calibration tier for the last 24 hours.

    tier-distribution.png
  • Parsed vs. Unparsed – This graphic shows what percentage of logs ingested in the last 24 hours have been successfully parsed versus what percentage have not been parsed.

    parsed-vs-unparsed.png