Skip to main content

Site CollectorSite Collector Administration Guide

Monitor Log Sources

Using the Log Source Monitoring feature, you can easily monitor log sources on Exabeam Security Operations Platform and get notified of any issues, which prevents you from missing out on timely detections and potential attack alerts.

In addition to timely monitoring of each log source, the Log Source Monitoring feature provides you with:

  • Notifications about the designated log source if the log source becomes inactive and stops to transmit logs

  • Data alerting upon issue occurrence and proactive monitoring techniques applied at log source level

  • Capability to view silent log source cases in last 24 hours

The following table describes each field displayed on the Log Sources tab. For each Collector instance, you can view the following information.

log_sources_1_1.png

Field

Description

Host

Source host or a virtual machine from where log source that is a piece of log information is delivered.

Collector Type

Type of the Collector: Windows Event Log, File, and Archive

Template

Name of the template that you used for your Collector instance.

Last Day Volume

The volume of raw log data or event logs from Windows Event Log collector, Windows File collector, Linux File collector, Windows Archive collector, and Linux Archive collector, for the last 24 hours.

Last Seen

The time when the the log source sent logs.

Status

The current status of the log source: Running, Silent, or Deleted.

  • Silent – If there is a significant drop in receiving logs from a source, that log source is considered as a Silent log source. The log sources are monitored every hour.

  • Running – If logs are received continuously from a source, the status of that log source is marked as Running.

  • Deleted – If the log source is deleted, the associated logs remain accessible for a limited time and the status of the log source is indicated as Deleted.

View Details

Detailed status information for the collector and error history for troubleshooting.