Skip to main content

Site CollectorSite Collector Administration Guide

View Site Collector Error Notifications

The Exabeam Security Operations Platform provides you with error notifications and notifications for time sensitive security and health issues for Site Collectors via user interface to monitor the status and health of your collectors. For more information see Notifications.

The Exabeam Security Operations Platform notifications service provides:

  • Precise error messages with metadata for consistent, clear, and actionable notifications

  • Configurability to minimize notification noise

  • Filters for improved notification management

  • Inbox for enhanced notification review

  • Additional external messaging channels

View Notifications for Site Collectors

The Exabeam Security Operations Platform notifications service includes error notifications about the Site Collectors service. To view the collector notifications, click the notifications icon (icon-notification.png).

The Site Collector notifications are generated when an error occurs in log ingestion or volume for any of the Site Collector or collector instance.

To view notifications about Site Collector errors:

  1. Log in to the Exabeam Security Operations Platform and click the Notifications icon (icon-notification.png) in the upper right corner.

  2. Click the Applications filter and select Cloud and Site Collectors.

    notifictaion_filter.png

    The notifications relevant for Cloud and Site Collectors are listed.

    notifictaion_filter2.png
  3. To view error details, click the Site Collectors link in the error notification.

    The specific collector instance displays error details.

    Scroll down to view full details of the error and the recommended action to resolve the error.

    errro_details2.png

    For notification type Inactive Site Collector and Silent Log Source, error details are displayed as follows.

    error_details__NGSC.png

    By default, these notifications are received in the application, but you can also choose to receive them via email. For more information, see Manage Notification Preferences.

    To configure group notification delivery via Teams, Slack, or web hooks, see Manage Global Notification Preferences.

    The following table displays the available collector notification types.

    Notification Type

    Description

    Collector Error

    Indicates cloud or site collector specific errors.

    Collector Volume Decreased

    Indicates that log volume has decreased.

    Collector Volume Increased

    Indicates that there is an increase in log volume.

    Site Collector Instance Certificate Expiration

    Indicates that the security certificate has expired or may expire in two weeks.

    Inactive Site Collector

    Indicates that the collector instance has not collected any logs in the past four hors.

Filter Notifications

To view notifications based on categories, applications, and severities for site collectors, apply relevant filters.

  • Categories

    category_filter.png
  • Applications

    Application_filter.png
  • Severities

    severities_filter.png

Manage Preferences for Notifications

You can manage preferences to view notifications. Based on what notifications you want to see in the Your Notifications pane, you can turn on or turn off the notification types such as notifications for collector error or notifications for collector volume. To view the Personal delivery preferences page and set preferences for notifications on collector errors, click the Settings icon (icon-settings.png).

Site_Collectors_notifications.png

View Inbox for Notification Review

To view the site collector notifications received over the last 90 days, click the Inbox icon (inbox_icon.png). You can view number of notifications classified as Critical, Warning, and Informational. You can apply various filters to the notification based on your preferences and requirement. You can also search for a particular notification. For more information see View Inbox.

inbox_notifictaions.png