Running Logfu on a Container

The Logfu utility is a diagnostic tool that parses ArcSight logs to generate an interactive visual representation of the information contained within the logs. When event flow problems occur, it can be useful to have a visual representation of what happened over time.

To run Logfu on a container:

  1. Click Node Management.

  2. In the navigation tree, navigate to the host on which the container resides.

  3. Click the Containers tab.

  4. On the Containers tab, locate a container on which to run Logfu.

  5. In the Action drop-down of the container, click Run Logfu.

  6. The Logfu progress window is displayed as system data logs are retrieved and analyzed. Data is then displayed by Group, Field, and Chart.

    • In the Group box, choose which type of data you would like to view. The Group box lists all connectors within the chosen container, plus many other types of data such as memory usage and transport rates.

    • Then, choose one of the Group box data points. Depending on which data point you chose, a list of fields appears in the Field box below.

    • Choose a field to view. A graphic chart appears in the Chart box, providing rate and time information. The key at the bottom of the Chart box defines the data points mapped in the chart.

    • To choose a different data point for analysis, click Reset Data.

  7. When complete, close the display window.