Skip to main content

Site CollectorSite Collector Administration Guide

Monitor Log Sources

Using the Log Source Monitoring feature, you can easily monitor log sources on Exabeam Security Operations Platform and get notified of any issues, which prevents you from missing out on timely detections and potential attack alerts.

In addition to timely monitoring of each log source, the Log Source Monitoring feature provides you with:

  • Notifications about the designated log source if the log source becomes inactive and stops to transmit logs

  • Data alerting upon issue occurrence and proactive monitoring techniques applied at log source level

  • Capability to view silent log source cases in last 24 hours

The following table describes each field displayed on the Log Sources tab. For each Collector instance, you can view the following information.

log_sources_1_1.png

Field

Description

Host

Source host or a virtual machine from which logs are sent to Site Collector.

Collector Type

Type of the Collector: Windows Event Log, File, and Archive

Template

Name of the template that you used for your Collector instance.

Last Day Volume

The volume of raw log data or event logs from Windows Event Log collector, Windows File collector, Linux File collector, Windows Archive collector, and Linux Archive collector, for the last 24 hours.

Last Seen

The time when the the log source sent logs.

Status

The current status of the log source: Running, Silent, or Deleted.

  • Silent – If there is a significant drop (75% or more drop in log volume in last 4 hours) in receiving logs from a source, that log source is considered as a Silent log source. The log sources are monitored every hour.

  • Running – If logs are received continuously from a source, the status of that log source is marked as Running.

  • Deleted – If the log source is deleted, the associated logs remain accessible for a limited time and the status of the log source is indicated as Deleted.

View Details

Detailed status information for the collector and error history for troubleshooting.

View Log Source Details

In the Log Sources section, you can view log source details such as status, type, host, last day volume, last seen, report of the silent log source, related collector and template, and the volume graph to indicate inactivity and reduction in log volume. You get In App notifications for the log sources that became Silent since last four hours.

A log source is a unique combination of an agent type, a template, and the host where it is deployed. Each log source represents a specific log category or type. For example, if a Windows Event Log Collector has two templates, one with security log events and the other with application log events deployed onto host 1 and host 2, four log sources are generated: host1 security events source, host2 security events source, host1 application events source, and host2 application events source.

To view log source details:

  1. On the Exabeam Security Operations Platform home page, click the Site Collectors tile.

  2. Click the Log Sources tab.

  3. On the Log Sources tab, click the host for which you want to view log source details.

    monitor_log_source_1.png

    Alternatively, click View Details.

    monitor_log_source_good_example.png
  4. After viewing the log source details, to view the associated collector instance, click View collector. Or, to view the template that the collector uses, click View template.

    view_log_sources_latest.png

    The log source details include status, type, host, last day volume, last seen, and a report of the silent log source. You can access the related collector and template. The volume section displays a graph to indicate volume of data ingested in past 24 hours for a log source.

View Notifications about Silent Log Sources

The notifications section that you can access by clicking the notifications icon (icon-notification.png), displays notifications for the log sources that became Silent since last four hours.

For example: The data volume for the Windows File log source on host 10.70.0.123 with template windows-file-abc decreased by more than 75% over the past 4 hours.

Example_inactive_SC_-_Silent_log_source.png

You get a notification every 2 hours for all the log sources that have Silent status as opposed to the log sources that are in Running and Deleted state.

If the sum of data ingested in the most recent four hours is 25% or lesser than the sum of data ingested in the preceding four hours, the log source is considered as silent and the relevant notifications are sent for that log source.

Refer to the following screenshot for an example of a notification about a silent log source.

silent_notification.png

Refer to the following screenshot for an example that indicates less volume of data ingested in past 20 hours for a log source.

log_volume_20_hours.png